Resolve confinement and ownership before destruction
A well-formed derived path is a candidate target, not permission to delete it.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
Cleanup receives a process-supplied job path under jobs/ for teaching identity J7. Other processes can write arguments; an apparent child may be a symlink or another job.
Mechanism
Canonicalize candidate and allowed roots, requiring a strict descendant/minimum depth, never root. Compare authenticated expected identity with protected ownership evidence, not writable .owner. Address check/use replacement using immutable controlled hierarchy or suitable safe handles. Reject without broader fallback; destructive action follows real authorization.
Bad example
Delete jobs/J7 because the OS supplied it; if absent delete jobs, trusting a self-written owner marker.
Good example
Treat the path as a candidate, resolve links and check scope/protected J7 ownership before race-safe operations. Stop on missing/mismatched/changed evidence without parent fallback. Verify in isolated fixtures, not by deleting real targets.
Why the change matters
Confinement answers where; ownership/authority answer whether. Resolution and race handling prevent benign names pointing outside scope or at someone else’s data.
Observable expectation
Teaching roots, external links, wrong owners and post-check substitution reject. A valid current-job child satisfies candidate conditions. Legitimate ..cache must not be rejected by a naive prefix check. Verify mechanisms, not names alone.
Limits
Handle/link behavior varies by platform and static checks cannot ensure race safety. Markers/digests are not authorization; disclose missing protection. No target was deleted/moved here.
Sources and evidence
- addyosmani/agent-skills · Resolve confinement and ownership before destruction
File at this version9d0c60d406b4