Repository navigation
Conversation
| '\\.claude\\/settings(\\.local)?\\.json', | ||
| '\\.claude\\.json', | ||
| // Built from the one list, so a hook file cannot be installed into and left unnamed here. | ||
| ...HOOK_FILE_PATHS.map((file) => file.replace(/\./g, '\\.')), |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #27.
What this changes
Memnox installs its policy hook into five files. It protected one. Measured on
main:So Cursor could edit
~/.cursor/hooks.json, drop the policy hook, andself-protection.tswould not refuse it — the agent removing its own guardrail, which is the one thing the module exists to stop. Same for Codex, Gemini CLI and Windsurf. With the change all five readyes.How it stays fixed
AGENT_HOOK_FILESis one list ingate/protected-paths.ts, exported from@memnox/core. The installer incli/src/protect/agent-hooks.tsbuilds its four paths from it,isProtectedPathmatches against it, andNAMES_PROTECTEDis now built from it rather than spelled out again. That is the shape the issue asks for: a file gaining a hook cannot be left unguarded, because the installer and the guard read the same line.It is segments rather than a joined string so the installer keeps using
join()and stays right on Windows, while the guard compares the posix spelling it already normalises to.How it was verified
Four shell lines, one per agent, each refused —
sed -i,rm,echo >,cp— and a table test asserting bothisProtectedPathandnamesProtectedfor every entry in the shared list, so a future entry is covered the moment it is added.Two negatives pin that this did not widen into the directories:
~/.cursor/rules.jsonand~/.codex/notes.jsonare still a person's ordinary files.prettier,tsc,vitestandknipall clean, on Node 24.What I did not do
The issue also mentions
intercept/os-guard.ts. The kernel profile is a separate list with its own shape, and the acceptance criteria stop at the gate, so I left it alone rather than guess at the seatbelt and Landlock wording. Worth its own issue if the four should be walled there too — happy to take it.Checklist
pnpm format && pnpm typecheck && pnpm test && pnpm deadcodeall passany, no magic values, noconsole.*outsidecli-output.ts