Skip to content

rm -rf hook does not catch find -exec rm -rf or xargs rm -rf #58

Description

@e-q

The rm -rf PreToolUse hook in settings.json:55 only recognizes rm at the start of the command string or immediately after ;, &&, ||, or |:

(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]

It doesn't catch the two forms an agent produces most naturally when told to clean up a tree:

find . -name '*.tmp' -exec rm -rf {} \;
find . -name '*.tmp' | xargs rm -rf

Neither has rm in a recognized position, so both pass. An rm after a newline in a multi-line command also passes.

README.md:236 frames hooks correctly as "guardrails, not walls," so this isn't a security boundary failing — but -exec and xargs are the first two shapes anyone hits, which makes the guardrail easy to over-trust.

Suggested fix

Either extend the position set to cover -exec and xargs (and a newline), or note the gap in the README so nobody assumes the hook covers indirect invocations.

Related: #48 identifies the same class of gap from the permissions side — deny rules not covering indirect writes. And #33 applied this kind of rigor to this hook already; this is two shapes that pattern didn't reach.

Aside

The permissions.deny entries Bash(rm -rf *) / Bash(rm -fr *) also don't cover rm -r -f, rm -Rf, or rm --recursive --force. Anthropic's docs do warn that argument-matching Bash patterns are inherently fragile, so the hook is the layer that matters — noting it only so the deny list isn't mistaken for coverage.


Found while reviewing the repo against Anthropic's current docs and the installed CLI (2.1.238). One of five separate findings from the same pass.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions