fix: add shell() helper, fix run() misuse across 13 tools - #63
Closed
TerminalGravity wants to merge 1 commit into
Closed
fix: add shell() helper, fix run() misuse across 13 tools#63TerminalGravity wants to merge 1 commit into
TerminalGravity wants to merge 1 commit into
Conversation
run() uses execFileSync('git', args) without a shell, but 13 tool files
were passing shell syntax (pipes, redirects, &&, ||) and non-git commands
(cat, find, wc, head, tail, command, tsc, gh) through it. These calls
would silently fail or produce wrong results since execFileSync without
shell:true treats pipes/redirects as literal arguments.
Added shell() to git.ts that uses execSync with a real shell for commands
that need pipes, redirects, or non-git binaries. Migrated all misused
run() calls to either:
- shell() for commands needing shell features
- run([...args]) array form for pure git commands (no shell needed)
Affected tools: audit-workspace, checkpoint, clarify-intent,
enrich-agent-task, scope-work, sequence-tasks, session-handoff,
session-health, sharpen-followup, token-audit, verify-completion,
what-changed
TerminalGravity
commented
Mar 3, 2026
TerminalGravity
left a comment
Collaborator
Author
There was a problem hiding this comment.
Reviewed — this looks solid. The silent failures from passing shell syntax through execFileSync were a real footgun. The shell() helper is clean: good timeout handling, proper error messages, sensible buffer limit. One thought: consider a brief JSDoc note about not passing user-controlled strings to avoid injection. Ready to merge.
Collaborator
Author
|
Closing — superseded by newer PRs. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
run()insrc/lib/git.tsusesexecFileSync('git', args)without a shell, but 13 tool files were passing shell syntax (pipes, redirects, &&, ||) and non-git commands (cat, find, wc, head, tail, tsc, gh) through it. These calls silently fail or produce wrong results.Fix
shell()export tosrc/lib/git.ts— usesexecSyncwith a real shellshell()orrun([...args])array formBuild clean, all 43 tests pass.