Skip to content

fix: chained-script false positive — usage examples in Python docstrings match interpreter pattern #213

Description

@jamessoubry

Problem

clawband's script file scanner flags Python docstrings as chained-script invocations. Usage examples inside """...""" blocks like:

#!/usr/bin/env python3
"""
Usage:
  python3 scripts/e2e_test.py --tenant jimmy-test
  python3 scripts/e2e_test.py --tenant jimmy-test --enrol
"""

trigger "script chains to another script: 'python3 scripts/e2e_test.py --tenant jimmy-test'" because ^\s*python3\s+<path> matches the usage lines — even though they're inside a docstring and never executed.

Root cause

The scanner has block-comment tracking (for /* */ and # style), but Python triple-quoted strings ("""...""" and '''...''') are not treated as non-executable regions. Any interpreter invocation pattern that appears inside a docstring fires the chained-execution check.

Expected behaviour

Content inside """...""" and '''...''' blocks should be skipped for chained-script and deny/ask pattern matching, the same way # comment lines are skipped. This applies when the scanner detects a .py file (by extension or shebang).

Workaround

Add the script to ~/.clawband/allow.patterns:

clawband allow 'python.*e2e_test\.py'

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions