Safety Rules
Critical: Read and follow all rules in this directory for every bash/command execution.
Core rules:
- Always set explicit
timeouton bash calls — 30s for tests, 60s for installs, never default - Never run unscoped full test suites — use
-kor file paths to limit scope - Never use
rm -rfwithout variable guards,curl|bash,sudo, orkill -9 - Infinite loops must have hard timeout + budget limits — no unbounded while(True)
- Redirect stdin with
< /dev/nullfor non-interactive commands
Rules
- rules/bash-safety.md - Bash command safety patterns and dangerous operations
- rules/bash-timeout.md - Timeout safety and terminal FD corruption prevention
- rules/terminal-safety.md - Terminal crash prevention and recovery
Incident Record
| Date | Incident | Root Cause | Prevention |
|---|---|---|---|
| 2026-05-08 | opencode TUI crash | bash timeout → SIGKILL → stdin FD corrupted → setRawMode errno: 9 | Always set explicit timeout; never SIGKILL |
See Also
/安检from an-jian — Security audit for dangerous patterns/skillsfrom skill-manager — Browse all installed skills