{"record":{"id":"f2c600db1ccb8425","repo":"Tencent/WeKnora","slug":"script-contains-dangerous-command","errorCode":null,"errorMessage":"script contains dangerous command","messagePattern":"script contains dangerous command","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/sandbox/sandbox.go","lineNumber":106,"sourceCode":"\t// (excluding user script execution which has its own per-call timeout).\n\tDefaultCubeHTTPTimeout = 30 * time.Second\n\n\t// DefaultE2BSandboxTTL matches the E2B SDK's built-in default so an\n\t// unset E2BSandboxTTL still yields a valid sandbox lifetime.\n\tDefaultE2BSandboxTTL = 5 * time.Minute\n\t// DefaultE2BHTTPTimeout bounds a single HTTP call to the E2B API.\n\tDefaultE2BHTTPTimeout = 30 * time.Second\n)\n\n// Common errors\nvar (\n\tErrSandboxDisabled   = errors.New(\"sandbox is disabled\")\n\tErrTimeout           = errors.New(\"execution timed out\")\n\tErrScriptNotFound    = errors.New(\"script not found\")\n\tErrInvalidScript     = errors.New(\"invalid script\")\n\tErrExecutionFailed   = errors.New(\"script execution failed\")\n\tErrSecurityViolation = errors.New(\"security validation failed\")\n\tErrDangerousCommand  = errors.New(\"script contains dangerous command\")\n\tErrArgInjection      = errors.New(\"argument injection detected\")\n\tErrStdinInjection    = errors.New(\"stdin injection detected\")\n)\n\n// Sandbox defines the interface for isolated script execution\ntype Sandbox interface {\n\t// Execute runs a script in an isolated environment\n\tExecute(ctx context.Context, config *ExecuteConfig) (*ExecuteResult, error)\n\n\t// Cleanup releases sandbox resources\n\tCleanup(ctx context.Context) error\n\n\t// Type returns the sandbox type\n\tType() SandboxType\n\n\t// IsAvailable checks if the sandbox is available for use\n\tIsAvailable(ctx context.Context) bool\n}","sourceCodeStart":88,"sourceCodeEnd":124,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/sandbox/sandbox.go#L88-L124","documentation":"Sentinel returned when the sandbox security scanner detects a dangerous command in the script (e.g. rm -rf, fork bombs, privileged/system-altering shell commands). The script is rejected before execution as a hard security control.","triggerScenarios":"Thrown at internal/sandbox/sandbox.go:106 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Rewrite the script to avoid the flagged dangerous command","Use sandbox-provided safe APIs instead of shell-level system operations","Review the scanner's blocklist to understand which pattern matched","Never attempt to obfuscate around the check — treat it as final"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}