{"record":{"id":"65818980626ad75f","repo":"paperclipai/paperclip","slug":"invalid-sandbox-environment-variable-key-key-658189","errorCode":null,"errorMessage":"Invalid sandbox environment variable key: ${key}","messagePattern":"Invalid sandbox environment variable key: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"packages/plugins/sandbox-providers/daytona/src/plugin.ts","lineNumber":873,"sourceCode":"    if (arg === \"submodule\") {\n      const next = args.slice(i + 1).find(a => !a.startsWith(\"-\"));\n      return next === \"update\";\n    }\n    return false;\n  }\n  return false;\n}\n\n// Build the one-shot exec command. Daytona's `executeCommand` runs the script\n// in a non-login shell, so it does not source `/etc/profile` on its own. The\n// Daytona reference image puts `node`, `claude`, and the other CLIs on the PATH\n// through `/etc/profile.d/00-restore-env.sh`, which only `/etc/profile` sources.\n// So the wrapper sources the login profiles itself; a non-login shell is then\n// enough to resolve the CLIs. The wrapper no longer sources `nvm.sh`; the\n// sandbox image supplies `node` on the PATH. See the sandbox runtime\n// requirements document.\nfunction buildLoginShellScript(input: {\n  command: string;\n  args: string[];\n  cwd?: string;\n  env?: Record<string, string>;\n  stdinPath?: string;\n}): string {\n  const callerEnv = input.env ?? {};\n  for (const key of Object.keys(callerEnv)) {\n    if (!isValidShellEnvKey(key)) {\n      throw new Error(`Invalid sandbox environment variable key: ${key}`);\n    }\n  }\n  // Caller env takes priority over noninteractive git credential defaults\n  const env = { ...NONINTERACTIVE_GIT_ENV, ...callerEnv };\n  const envArgs = Object.entries(env)\n    .filter((entry): entry is [string, string] => typeof entry[1] === \"string\")\n    .map(([key, value]) => `${key}=${shellQuote(value)}`);\n  const commandParts = [shellQuote(input.command), ...input.args.map(shellQuote)].join(\" \");\n  const redirectedCommand = input.stdinPath","sourceCodeStart":855,"sourceCodeEnd":891,"githubUrl":"https://github.com/paperclipai/paperclip/blob/3f1d897a7c018d76563a21c6e39c3c9b03933622/packages/plugins/sandbox-providers/daytona/src/plugin.ts#L855-L891","documentation":"Env-key sanitization in buildLoginShellScript for the Daytona driver: an environment variable key failed isValidShellEnvKey, which rejects keys that are not valid identifiers for the generated login-shell export line. This blocks shell metacharacter injection through env var names before the command string is assembled.","triggerScenarios":"Thrown at packages/plugins/sandbox-providers/daytona/src/plugin.ts:826 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Use a valid environment variable key (letters, digits, underscore, not starting with a digit)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"3f1d897a7c018d76563a21c6e39c3c9b03933622","analyzedAt":"2026-08-18T22:49:45.177Z","contentChangedAt":"2026-08-18T22:49:45.177Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}