Files
Trevin ChowandClaude Opus 4.7 8605e0f96c fix(skills): replace shell antipatterns blocked by permission check
Two safety-check rejections in `!` backtick pre-resolutions were
breaking skill-load in Claude Code:

- `[A] && B || C` shape ("ambiguous syntax with command separators",
  issue #710): ce-setup, ce-update, ce-work-beta/codex-delegation-workflow.
- `$()` containing a double-quoted string ("Unhandled node type:
  string", issue #709): ce-compound, ce-sessions, ce-update, ce-work-beta.

Replaces each with a safe shape: raw env-var emit, pure-pipe sed,
`${var%suffix}` parameter expansion, or an extracted script under the
skill's `scripts/`. ce-update gets three scripts (upstream-version,
currently-loaded-version, marketplace-name) since it's Claude-only
and has the most complex pre-resolution logic.

Adds regression tests in tests/skill-shell-safety.test.ts that flag
both antipatterns at PR time, and updates AGENTS.md to enumerate the
rejected shapes alongside the existing `case`/`esac` rule.

Closes #709, #710.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-27 21:05:03 -07:00
..