36 lines
1.3 KiB
Rust
36 lines
1.3 KiB
Rust
//! Tool usage patterns — detect dangerous or suspicious tool invocations.
|
|||
|
|
|
||
|
|
/// Check whether a tool invocation matches a known dangerous pattern.
|
||
|
|
///
|
||
|
|
/// Returns a description of the risk if the pattern matches, or `None`
|
||
|
|
/// if the invocation appears safe.
|
||
|
|
pub fn check_dangerous_pattern(tool_name: &str, args: &serde_json::Value) -> Option<String> {
|
||
|
|
match tool_name {
|
||
|
|
"bash" => {
|
||
|
|
let cmd = args
|
||
|
|
.get("command")
|
||
|
|
.and_then(|v| v.as_str())
|
||
|
|
.unwrap_or("");
|
||
|
|
// Detect git push with --force
|
||
|
|
if cmd.contains("git push") && cmd.contains("--force") {
|
||
|
|
return Some("Force-pushing to git is destructive and may lose history".to_string());
|
||
|
|
}
|
||
|
|
// Detect rm -rf /
|
||
|
|
if cmd.contains("rm -rf /") || cmd.contains("rm -rf /*") {
|
||
|
|
return Some("Recursive deletion of the root filesystem is never allowed".to_string());
|
||
|
|
}
|
||
|
|
}
|
||
|
|
"delete" => {
|
||
|
|
let path = args
|
||
|
|
.get("path")
|
||
|
|
.and_then(|v| v.as_str())
|
||
|
|
.unwrap_or("");
|
||
|
|
if path == "/" || path.starts_with("/etc") {
|
||
|
|
return Some(format!("Deleting '{}' is too dangerous", path));
|
||
|
|
}
|
||
|
|
}
|
||
|
|
_ => {}
|
||
|
|
}
|
||
|
|
None
|
||
|
|
}
|