diff --git a/deslop-shared-libs/SKILL.md b/deslop-shared-libs/SKILL.md index dd0b7a45a..9a5fbead3 100644 --- a/deslop-shared-libs/SKILL.md +++ b/deslop-shared-libs/SKILL.md @@ -72,7 +72,7 @@ changed after writing one. protections and refuses reads that could run filters, drivers, hooks or transports, naming the allowed forms. Never bypass a refusal with raw `git`. `diff` takes exactly two explicit committed object IDs, then `--` and paths. - First probe with `~/.claude/skills/gstack/bin/gstack-safe-git rev-parse --is-inside-work-tree`; a Git + First probe the audited repository with `~/.claude/skills/gstack/bin/gstack-safe-git -C rev-parse --is-inside-work-tree` (use `-C ` on every call when your shell is elsewhere); a Git version check alone is insufficient. If the probe fails (for example `unknown option: --no-lazy-fetch`), use pinned-commit GET API source and history reads or disclose unavailable local-history coverage. Never retry diff --git a/deslop-shared-libs/SKILL.md.tmpl b/deslop-shared-libs/SKILL.md.tmpl index d85a53e9d..29cf64c5d 100644 --- a/deslop-shared-libs/SKILL.md.tmpl +++ b/deslop-shared-libs/SKILL.md.tmpl @@ -66,7 +66,7 @@ changed after writing one. protections and refuses reads that could run filters, drivers, hooks or transports, naming the allowed forms. Never bypass a refusal with raw `git`. `diff` takes exactly two explicit committed object IDs, then `--` and paths. - First probe with `{{SAFE_GIT}} rev-parse --is-inside-work-tree`; a Git + First probe the audited repository with `{{SAFE_GIT}} -C rev-parse --is-inside-work-tree` (use `-C ` on every call when your shell is elsewhere); a Git version check alone is insufficient. If the probe fails (for example `unknown option: --no-lazy-fetch`), use pinned-commit GET API source and history reads or disclose unavailable local-history coverage. Never retry diff --git a/test/shared-libs-fixture.test.ts b/test/shared-libs-fixture.test.ts index e847be614..15c798a72 100644 --- a/test/shared-libs-fixture.test.ts +++ b/test/shared-libs-fixture.test.ts @@ -36,7 +36,7 @@ describe('shared-code Git guard', () => { installSourceShims(f); const instructions = fs.readFileSync(standaloneInstructions(f), 'utf8'); const helper = path.join(SHARED_LIBS_ROOT, 'bin/gstack-safe-git'); - expect(instructions).toContain(`\`${helper} rev-parse --is-inside-work-tree\``); + expect(instructions).toContain(`\`${helper} -C rev-parse --is-inside-work-tree\``); expect(instructions).not.toContain('~/.claude/skills/gstack'); const run = (command: string, args: string[]) => spawnSync(command, args, { cwd: f.repo, encoding: 'utf8', timeout: 10_000, env: { ...process.env, ...f.env } }); diff --git a/test/shared-libs-rendering.test.ts b/test/shared-libs-rendering.test.ts index c750ecc75..b2c80d95f 100644 --- a/test/shared-libs-rendering.test.ts +++ b/test/shared-libs-rendering.test.ts @@ -56,7 +56,7 @@ describe('shared-code skill distribution', () => { expect(standalone).toContain('Keep API responses and intermediate data on stdout or in memory'); // Git safety is the installed helper from the trusted global runtime, not a retyped prefix. const safeGit = `~/${host.globalRoot}/bin/gstack-safe-git`; - expect(standalone).toContain(`${safeGit} rev-parse --is-inside-work-tree`); + expect(standalone).toContain(`${safeGit} -C rev-parse --is-inside-work-tree`); expect(standalone).toContain(`${safeGit} ls-files --cached --others --exclude-standard -z`); expect(standalone).toContain('never bare `git`'); expect(standalone).not.toContain('git --no-pager');