Skip to content

feat: show extracted subprocess calls in chained-execution ask message #209

Description

@jamessoubry

Problem

When clawband detects that a script chains to other scripts (chained execution, v2.94.0), it prompts:

script chains to another script: 'python scripts/setup_tenant.py' — contents not scanned

The user has to open the script themselves to see what subprocesses it calls before deciding whether to approve.

Proposed behaviour

Extract the subprocess/exec calls from the script during the scan and include them in the ask message, e.g.:

script chains to other processes — contents not fully scannable
  python scripts/setup_tenant.py calls:
    subprocess.run(["aws", "ecs", ...])
    subprocess.run(["terraform", ...])
    os.system("docker build ...")
Approve to run anyway?

This gives the user enough context to make an informed decision without needing to read the source file.

Implementation notes

  • Reuse the existing script scanner; add a second pass to extract subprocess.run/Popen/os.system/os.exec*/check_call/check_output call sites
  • For shell scripts: extract bash/sh/python/node invocations
  • Cap the list at ~5 entries with "and N more" to keep the message readable
  • Only show this in the ask message — no behaviour change for deny or allow tiers

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions