github kenryu42/cc-safety-net v2.4.13

3 hours ago

This release closes a set of integration gaps where shell commands and file paths reached hosts without being analyzed, and makes installation and doctor report each host's real state instead of trusting its config file.

Highlights

  • Shell commands run through Claude Code's Monitor, Grok Build's monitor, and Pi's powershell tools are now analyzed for destructive commands. Previously those tools were routed as non-command tools, so a command such as git reset --hard was allowed through. (#163)
  • Tool inputs that name files in a paths array, a download destination, or a bare patch string are now inspected, so a Copilot CLI search or patch and an Amp thread download can no longer read or write protected paths unchecked. (#164, #166)

Added

  • Added OpenCode v1's global ~/.config/opencode/config.json to the protected OpenCode configuration paths. (#173)

Changed

  • Changed OpenCode v2 detection so doctor and the policy GUI ask the host for activation state with opencode api plugin.list and report a plugin OpenCode marked failed as not configured, instead of reporting it as configured from the config file alone. These commands may start OpenCode's persistent background service. (#171, #173)
  • Changed the OpenCode v2 installer to run opencode plugin add first, run opencode plugin update only when the plugin was already configured, wait for the host to list the plugin, and then confirm an active copy. The install now fails with OpenCode's own error when the plugin failed, and fails when the host lists no active copy. (#169, #173)
  • Changed the Codex entry in doctor to state that Codex runs only trusted hooks and that doctor cannot check trust, alongside the /hooks trust step. (#171)
  • Documented two analysis limits in SECURITY.md and the README: Codex's exec_command payload omits the call's workdir, and OpenClaw's before_tool_call context exposes no session directory, so on those hosts a command can be analyzed against a different directory than the one it runs in. (#172)

Fixed

  • Fixed Copilot CLI hook input handling so an object toolArgs is used as received, an apply_patch payload that arrives as raw *** Begin Patch text is analyzed as a patch, and Copilot's Bash tool is analyzed with shell auto-detection. (#166)
  • Fixed Copilot CLI detection to read repository-level enabledPlugins, to count hook entries that omit type or use exec and args, and to keep a standalone hook reported as configured when a repository switches the plugin off. (#171)
  • Fixed Gemini CLI analysis to use the directory named by run_shell_command's dir_path rather than the session directory. (#168)
  • Fixed Hermes so file-tool calls are analyzed in the directory Hermes resolves their relative paths against, and so installation targets the profile named in active_profile. (#167)
  • Fixed host-configuration discovery to follow CLAUDE_CONFIG_DIR, PI_CODING_AGENT_DIR, and OPENCLAW_HOME instead of assuming ~/.claude, ~/.pi/agent, and the OS home directory. (#170, #171)
  • Fixed OpenCode v2 first installation, which failed because opencode plugin update ran against a plugin that was not configured yet. (#169)
  • Fixed OpenCode v1 plugin discovery when OPENCODE_CONFIG_DIR is set: detection and uninstall now also scan the XDG configuration directory that v1 loads. (#169)
  • Fixed a ~ working directory on OpenCode v2 so it resolves to the home directory, matching the host, instead of a literal ~ directory inside the project. (#169)
  • Fixed an OpenClaw reinstall after an uninstall, which left the plugin disabled. Installation now enables it and accepts an enable the Gateway saved before a newer configuration reload superseded it. (#170, #173)

Don't miss a new cc-safety-net release

NewReleases is sending notifications on new releases.