17 lines
779 B
Markdown
17 lines
779 B
Markdown
# Bug Report — port-pi-guard
|
|||
|
|
|
||
|
|
## Review Scope
|
||
|
|
Pi dev guard plugin (guard.ts, package.json), integration in register-guards.sh and harness-integration.md.
|
||
|
|
|
||
|
|
## Findings
|
||
|
|
|
||
|
|
### No Critical Bugs Found
|
||
|
|
The guard.ts properly implements the pi ExtensionAPI pattern with `pi.on("tool_call", ...)`. It correctly intercepts edit/write/bash tools, calls status.py, and returns block responses. The fallback to allowing when status.py is unavailable is reasonable (fail-open for offline scenarios).
|
||
|
|
|
||
|
|
### Minor Observations
|
||
|
|
- Lines 38-40 contain unreachable dead code (the import is shadowed by the child_process import below)
|
||
|
|
- The bash tool regex check (`\b(write|tee|cp|mv|sed\b.*-i|dd\b.*of=)\b`) could miss some write patterns
|
||
|
|
|
||
|
|
## Verdict
|
||
|
|
No blocking bugs. Ready for adversarial review.
|