Skip to content

fix(rules): CSKILL pattern-blindness on CSKILL-050 and CSKILL-082 - #150

Merged
sairenchristianbuerano merged 1 commit into
mainfrom
fix/cskill-050-pattern-and-oai-tracing
Sep 21, 2026
Merged

sairenchristianbuerano merged 1 commit into
mainfrom
fix/cskill-050-pattern-and-oai-tracing

Conversation

@ivanpaghubasan

Copy link
Copy Markdown
Collaborator

Both rules matched on tool name only, never the grant Pattern, so a narrowly-scoped grant like Bash(git status:) fired identically to unrestricted Bash(). Switched to skill_allows_unrestricted_tool, which respects Claude Code's real per-tool permission semantics — Bash/PowerShell/WebFetch/Edit have genuine pattern restrictions, Write/NotebookEdit path rules are accepted but never consulted so those remain always-unrestricted.

Old skill_allows_tool key retained (now documented as pattern-blind) per the predicate-renaming discipline. Schema version bumped 16 -> 17.

Mirrored byte-for-byte from the engine fixture.

Both rules matched on tool name only, never the grant Pattern, so a
narrowly-scoped grant like Bash(git status:*) fired identically to
unrestricted Bash(*). Switched to skill_allows_unrestricted_tool,
which respects Claude Code's real per-tool permission semantics —
Bash/PowerShell/WebFetch/Edit have genuine pattern restrictions,
Write/NotebookEdit path rules are accepted but never consulted so
those remain always-unrestricted.

Old skill_allows_tool key retained (now documented as pattern-blind)
per the predicate-renaming discipline. Schema version bumped 16 -> 17.

Mirrored byte-for-byte from the engine fixture.
@sairenchristianbuerano
sairenchristianbuerano merged commit 6df8a3d into main Sep 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants