forbidden_symbol_scan: braced zle params bypass it, and it never checks it scanned anything #14

closed cmc opened this on 2026-09-04 16:47 UTC

cmc 2026-09-04 16:47 UTC

Two defects in the privacy ship-gate.

text.contains("$BUFFER") does not match ${BUFFER}, which is valid zsh — so the check enforcing the project's central claim is sidestepped by two characters. $RBUFFER is not in the list at all.

The scan also asserts nothing about having scanned. If walk() returns empty for any reason the test passes green having read zero files, which reports success while checking nothing.

Done when:

  • Braced forms and RBUFFER are covered.
  • The scan asserts it visited a non-zero number of files, including known ones.
  • The API list is widened by prefix where that is safe: CGEvent, IOHID, addLocalMonitorForEvents, AXObserver, AXUIElement.
  • Bare NSEvent stays allowed: the post-1.0 menu-bar pet needs it for UI, and the keylogger-shaped API is the monitor, not the class.

closed by commit 3c8c952802 by cmc: Close two holes in the privacy ship-gate

2026-09-04 16:50 UTC