Two defects in the privacy ship-gate.
text.contains("$BUFFER") does not match ${BUFFER}, which is valid zsh — so the check enforcing the project's central claim is sidestepped by two characters. $RBUFFER is not in the list at all.
The scan also asserts nothing about having scanned. If walk() returns empty for any reason the test passes green having read zero files, which reports success while checking nothing.
Done when:
- Braced forms and
RBUFFERare covered. - The scan asserts it visited a non-zero number of files, including known ones.
- The API list is widened by prefix where that is safe:
CGEvent,IOHID,addLocalMonitorForEvents,AXObserver,AXUIElement. - Bare
NSEventstays allowed: the post-1.0 menu-bar pet needs it for UI, and the keylogger-shaped API is the monitor, not the class.
closed by commit 3c8c952802 by cmc: Close two holes in the privacy ship-gate
2026-09-04 16:50 UTC