added some regex based checks for dangerous commands (#38)
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
from pathlib import Path
|
||||
from subprocess import CompletedProcess, run
|
||||
from typing import List
|
||||
from goose.utils.check_shell_command import is_dangerous_command
|
||||
|
||||
from exchange import Message
|
||||
from rich import box
|
||||
@@ -135,7 +136,7 @@ class Developer(Toolkit):
|
||||
command (str): The shell command to run. It can support multiline statements
|
||||
if you need to run more than one at a time
|
||||
"""
|
||||
self.notifier.status("running shell command")
|
||||
self.notifier.status("planning to run shell command")
|
||||
# Log the command being executed in a visually structured format (Markdown).
|
||||
# The `.log` method is used here to log the command execution in the application's UX
|
||||
# this method is dynamically attached to functions in the Goose framework to handle user-visible
|
||||
@@ -156,13 +157,13 @@ class Developer(Toolkit):
|
||||
rating = int(rating)
|
||||
except ValueError:
|
||||
rating = 5 # if we can't interpret we default to unsafe
|
||||
if int(rating) > 3:
|
||||
if is_dangerous_command(command) or int(rating) > 3:
|
||||
if not keep_unsafe_command_prompt(command):
|
||||
raise RuntimeError(
|
||||
f"The command {command} was rejected as dangerous by the user."
|
||||
+ " Do not proceed further, instead ask for instructions."
|
||||
)
|
||||
|
||||
self.notifier.status("running shell command")
|
||||
result: CompletedProcess = run(command, shell=True, text=True, capture_output=True, check=False)
|
||||
if result.returncode == 0:
|
||||
output = "Command succeeded"
|
||||
|
||||
Reference in New Issue
Block a user