What's wrong with this entry?
The shell command security analyzer has been significantly rewritten to use tree-sitter AST analysis instead of relying solely on string-based heuristics. When tree-sitter is available, it provides authoritative quote context analysis, compound structure detection, and dangerous pattern identification.
New security checks include:
- Arithmetic expansion with variable references
- Heredocs with unquoted delimiters (shell expansion risk)
- Brace expansion syntax detection
- IFS assignment (word-splitting changes)
- Tilde expansion in assignment values
- Unicode whitespace and control character detection
- Zsh
~[dynamic directory syntax - Shell keyword misuse detection
When tree-sitter is unavailable, falls back to the legacy shell-quote parser with a log message: "tree-sitter unavailable, using legacy shell-quote path".
New analyzer functions (search for "Tree-sitter quote context is authoritative", "Brace expansion", "IFS assignment")
Strings lifted out of the shipped bundle, so the claim above can be checked against them.