Skip to content

fix(node): pass paths to child processes as arguments, not shell strings - #268

Merged
Rome-1 merged 1 commit into
mainfrom
mayor-agent/gemini-link-no-shell
Oct 2, 2026
Merged

Rome-1 merged 1 commit into
mainfrom
mayor-agent/gemini-link-no-shell

Conversation

@Rome-1

@Rome-1 Rome-1 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

rafter agent init --with-gemini registered skills by running gemini skills link "<path>" as a shell string, with the path quoted by JSON.stringify.
Double quotes do not stop a POSIX shell from expanding $(...) or backticks, and with --local the path is under the working directory.

  • init.ts: run gemini with an argument array (execFileSync). On Windows the call keeps cmd.exe, which it needs to run gemini's .cmd shim and which treats a double-quoted path literally.
  • install-hook.ts: the global git config core.hooksPath call uses an argument array.
  • status.ts: the local betterleaks version probe uses an argument array.

The last two are rooted in the home directory; they change for consistency.
The Python CLI already passes these as argument lists and is unaffected.

Test

node/tests/agent-init-gemini-link.test.ts runs the built CLI's agent init --local --with-gemini from a temporary directory whose name contains shell syntax, with a stub gemini on PATH that logs its arguments.
It asserts the skill path reaches gemini as one literal argument and that the embedded command did not run.
It fails on main and passes on this branch (skipped on Windows).

tsc clean. Node suite: 2275 passed; the 3 Cursor hook tests that fail also fail on main in a local checkout and are unrelated.

`agent init --with-gemini` built `gemini skills link "<path>"` as a
shell string, quoting the path with JSON.stringify. Double quotes do not
stop a POSIX shell from expanding $(...) or backticks, and the path comes
from the working directory. Run gemini with an argument array instead;
Windows keeps cmd.exe, which it needs for gemini's .cmd shim and which
treats a double-quoted path literally.

Same change for two siblings rooted in the home directory: the global
`git config core.hooksPath` call in install-hook and the local
betterleaks version probe in status.

Adds an end-to-end test that runs init from a directory whose name
contains shell syntax, with a stub gemini on PATH, and asserts the path
arrives literally and nothing is executed.
@Rome-1
Rome-1 merged commit f0e7533 into main Oct 2, 2026
10 checks passed
@Rome-1
Rome-1 deleted the mayor-agent/gemini-link-no-shell branch October 2, 2026 04:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant