//! Tool usage patterns — detect dangerous or suspicious tool invocations. /// Check whether a tool invocation matches a known dangerous pattern. /// /// Returns a description of the risk if the pattern matches, or `None` /// if the invocation appears safe. pub fn check_dangerous_pattern(tool_name: &str, args: &serde_json::Value) -> Option { match tool_name { "bash" => { let cmd = args .get("command") .and_then(|v| v.as_str()) .unwrap_or(""); // Detect git push with --force if cmd.contains("git push") && cmd.contains("--force") { return Some("Force-pushing to git is destructive and may lose history".to_string()); } // Detect rm -rf / if cmd.contains("rm -rf /") || cmd.contains("rm -rf /*") { return Some("Recursive deletion of the root filesystem is never allowed".to_string()); } } "delete" => { let path = args .get("path") .and_then(|v| v.as_str()) .unwrap_or(""); if path == "/" || path.starts_with("/etc") { return Some(format!("Deleting '{}' is too dangerous", path)); } } _ => { tracing::debug!("no guard pattern registered for tool: {tool_name}"); } } None }