Pass review artifacts through inert input channels
Preserve artifact text as data when invoking an external reviewer.
These examples and illustrative results are independently authored teaching materials, not measured model results.
Use case
An authorized external review reads code with quotes, backticks and command-substitution syntax. Shell interpolation can execute the artifact before it reaches the reviewer as data.
Mechanism
Verify trusted binary/version, read-only capability and sharing authorization. Write artifact/contract through file APIs and pass via file/stdin or structured shell-free arguments. Preserve separate argv entries; JSON.stringify is not shell escaping. Record artifact digest/invocation/result and label content data while limiting inherited environment/effects.
Bad example
Interpolate code into shell -p and assume double quotes neutralize every backtick/substitution.
Good example
Write exact artifact/contract to a file, pass it through the verified reviewer’s stdin/read-only boundary and separate argv. Metacharacters arrive inert. Verify sharing scope/environment/results instead of trusting wrapper names as sandbox guarantees.
Why the change matters
Files/stdin separate material from command grammar. Read-only/provenance controls address runtime behavior but do not replace untrusted-input labeling.
Observable expectation
Teaching metacharacter sentinels arrive intact with zero command execution. Received bytes match source and reviewer does not modify the target tree. Without invocation report preparation/check plans, not results.
Limits
Inert shell transport does not remove prompt injection or external disclosure. Verify real flags/environment/platform contracts. Frozen command shapes are illustrative; no external reviewer CLI ran here.
Sources and evidence
- addyosmani/agent-skills · Pass review artifacts through inert input channels
File at this version9d0c60d406b4 - affaan-m/ECC · Executable and argument boundaries
File at this versionef648e01899b