MCPcopy Create free account
hub / github.com/codeaashu/claude-code / validateProcEnvironAccess

Function validateProcEnvironAccess

src/tools/BashTool/bashSecurity.ts:1041–1067  ·  view source on GitHub ↗
(
  context: ValidationContext,
)

Source from the content-addressed store, hash-verified

1039// Path validation typically blocks /proc access, but this provides defense-in-depth.
1040// Environment files in /proc can expose sensitive data like API keys and secrets.
1041function validateProcEnvironAccess(
1042 context: ValidationContext,
1043): PermissionResult {
1044 const { originalCommand } = context
1045
1046 // Check for /proc paths that could expose environment variables
1047 // This catches patterns like:
1048 // - /proc/self/environ
1049 // - /proc/1/environ
1050 // - /proc/*/environ (with any PID)
1051 if (/\/proc\/.*\/environ/.test(originalCommand)) {
1052 logEvent('tengu_bash_security_check_triggered', {
1053 checkId: BASH_SECURITY_CHECK_IDS.PROC_ENVIRON_ACCESS,
1054 subId: 1,
1055 })
1056 return {
1057 behavior: 'ask',
1058 message:
1059 'Command accesses /proc/*/environ which could expose sensitive environment variables',
1060 }
1061 }
1062
1063 return {
1064 behavior: 'passthrough',
1065 message: 'No /proc/environ access detected',
1066 }
1067}
1068
1069/**
1070 * Detects commands with malformed tokens (unbalanced delimiters) combined with

Callers

nothing calls this directly

Calls 1

logEventFunction · 0.85

Tested by

no test coverage detected