What's wrong with this entry?
Anonymous. No account, no email.
New Zsh-specific and general shell security checks for the Bash tool:
- Zsh process substitution
=()— detected and flagged - Zsh glob qualifiers with command execution
(+— detected and flagged - Zsh
try/alwaysconstructs} always {— detected and flagged - Dangerous Zsh builtins (
zmodload,zpty,ztcp,zsocket,zf_rm, etc.) — blocked fc -ecommand detection — prevents arbitrary command execution via editor- Backslash-escaped operators — detects
\;,\|,\&,\<,\>outside quotes that can hide command structure - Comment quote desync — detects quote characters inside
#comments that can confuse quote tracking - Tilde expansion variants (
~user,~+,~-) — require manual approval - Compound
cd+gitcommands — flagged to prevent bare repository attacks
Evidence
Security check functions (search for "Zsh process substitution", "backslash-escaped operators", "comment quote desync", "fc -e")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.