kodebeat / papers / security
Judging a shell command's blast radius before it runs
A risk scorer for shell commands, with the factors shown.
Scores a command 0 to 100 before it runs, with a blast radius, a reversibility verdict and every factor that contributed, so you can disagree with it. It scores binary, flags, target and context rather than matching a deny-list, and recurses into pipelines, scripts and payloads carried through ssh, docker exec and sh -c. A safety tool for commands written in good faith, explicitly not a sandbox.
What is in it
- The problem — what goes unanswered without it, and who notices first.
- Why the obvious alternative falls short — stated plainly, including where it is the better choice.
- How it works — the method, not a feature list.
- Concrete use cases — with console output quoted from the repository, never reconstructed.
- The methodology behind any number it emits — every term shown, so the figure survives a question.
- What it deliberately does not do — the section most papers leave out.
Part of the Security & supply chain theme.
Get the PDF
One email with the download link, and this paper already selected. No follow-up sequence.