P250 · Safety & trust

Pass review artifacts through inert input channels

Preserve artifact text as data when invoking an external reviewer.

Editorially reviewed

These examples and illustrative results are independently authored teaching materials, not measured model results.

Use case

An authorized external review reads code with quotes, backticks and command-substitution syntax. Shell interpolation can execute the artifact before it reaches the reviewer as data.

Mechanism

Verify trusted binary/version, read-only capability and sharing authorization. Write artifact/contract through file APIs and pass via file/stdin or structured shell-free arguments. Preserve separate argv entries; JSON.stringify is not shell escaping. Record artifact digest/invocation/result and label content data while limiting inherited environment/effects.

Bad example

Interpolate code into shell -p and assume double quotes neutralize every backtick/substitution.

Good example

Write exact artifact/contract to a file, pass it through the verified reviewer’s stdin/read-only boundary and separate argv. Metacharacters arrive inert. Verify sharing scope/environment/results instead of trusting wrapper names as sandbox guarantees.

Why the change matters

Files/stdin separate material from command grammar. Read-only/provenance controls address runtime behavior but do not replace untrusted-input labeling.

Observable expectation

Teaching metacharacter sentinels arrive intact with zero command execution. Received bytes match source and reviewer does not modify the target tree. Without invocation report preparation/check plans, not results.

Limits

Inert shell transport does not remove prompt injection or external disclosure. Verify real flags/environment/platform contracts. Frozen command shapes are illustrative; no external reviewer CLI ran here.

Sources and evidence

Read the editorial criteria