23 lines
573 B
Python
23 lines
573 B
Python
# retoor <retoor@molodetz.nl>
|
|||
|
|
import json
|
||
|
|
import re
|
||
|
|
import sys
|
||
|
|
|
||
|
|
PROTECTED = re.compile(r"(\bdata/|molodetz\.db|\.env\b|rm\s+-rf\s+/|DROP\s+TABLE|git\s+push\s+--force)", re.IGNORECASE)
|
||
|
|
|
||
|
|
|
||
|
|
def main():
|
||
|
|
try:
|
||
|
|
event = json.load(sys.stdin)
|
||
|
|
except json.JSONDecodeError:
|
||
|
|
return 0
|
||
|
|
command = json.dumps(event.get("tool_input", event))
|
||
|
|
if PROTECTED.search(command):
|
||
|
|
print("prod_guard: command touches production data or secrets; confirm manually.", file=sys.stderr)
|
||
|
|
return 2
|
||
|
|
return 0
|
||
|
|
|
||
|
|
|
||
|
|
if __name__ == "__main__":
|
||
|
|
sys.exit(main())
|