Skip to content

Commit bac1a39

Browse files
nawi-25claude
andcommitted
feat: context sniper UI, browser gating, Apache-2.0, Claude AI review
- native.ts: add extractContext + formatArgs with matchedField/matchedWord tracing for "Context Sniper" popup — shows dangerous word in context - core.ts: extend evaluatePolicy return with matchedField/matchedWord; per-field scan after dangerous word found; pass through authorizeHeadless - daemon/index.ts: gate SSE broadcast and browser open on browser config flag - LICENSE/package.json/README.md: MIT → Apache-2.0 - .github/workflows/ai-review.yml: add paths-ignore to prevent self-modification - scripts/ai-review.mjs: upgrade to claude-sonnet-4-6, max_tokens 2048 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent a2ea754 commit bac1a39

9 files changed

Lines changed: 565 additions & 89 deletions

File tree

.github/workflows/ai-review.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,9 @@ name: AI Code Review
33
on:
44
pull_request:
55
branches: [main]
6+
paths-ignore:
7+
- '.github/workflows/ai-review.yml'
8+
- 'scripts/ai-review.mjs'
69

710
jobs:
811
review:

LICENSE

Lines changed: 183 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,21 +1,183 @@
1-
MIT License
2-
3-
Copyright (c) 2026 nadav-node9
4-
5-
Permission is hereby granted, free of charge, to any person obtaining a copy
6-
of this software and associated documentation files (the "Software"), to deal
7-
in the Software without restriction, including without limitation the rights
8-
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
9-
copies of the Software, and to permit persons to whom the Software is
10-
furnished to do so, subject to the following conditions:
11-
12-
The above copyright notice and this permission notice shall be included in all
13-
copies or substantial portions of the Software.
14-
15-
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
16-
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
17-
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
18-
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
19-
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
20-
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21-
SOFTWARE.
1+
Apache License
2+
Version 2.0, January 2004
3+
http://www.apache.org/licenses/
4+
5+
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
6+
7+
1. Definitions.
8+
9+
"License" shall mean the terms and conditions for use, reproduction,
10+
and distribution as defined by Sections 1 through 9 of this document.
11+
12+
"Licensor" shall mean the copyright owner or entity authorized by
13+
the copyright owner that is granting the License.
14+
15+
"Legal Entity" shall mean the union of the acting entity and all
16+
other entities that control, are controlled by, or are under common
17+
control with that entity. For the purposes of this definition,
18+
"control" means (i) the power, direct or indirect, to cause the
19+
direction or management of such entity, whether by contract or
20+
otherwise, or (ii) ownership of fifty percent (50%) or more of the
21+
outstanding shares, or (iii) beneficial ownership of such entity.
22+
23+
"You" (or "Your") shall mean an individual or Legal Entity
24+
exercising permissions granted by this License.
25+
26+
"Source" form shall mean the preferred form for making modifications,
27+
including but not limited to software source code, documentation
28+
source, and configuration files.
29+
30+
"Object" form shall mean any form resulting from mechanical
31+
transformation or translation of a Source form, including but
32+
not limited to compiled object code, generated documentation,
33+
and conversions to other media types.
34+
35+
"Work" shall mean the work of authorship made available under
36+
the License, as indicated by a copyright notice that is included in
37+
or attached to the work (an example is provided in the Appendix below).
38+
39+
"Derivative Works" shall mean any work, whether in Source or Object
40+
form, that is based on (or derived from) the Work and for which the
41+
editorial revisions, annotations, elaborations, or other transformations
42+
represent, as a whole, an original work of authorship. For the purposes
43+
of this License, Derivative Works shall not include works that remain
44+
separable from, or merely link (or bind by name) to the interfaces of,
45+
the Work and the Derivative Works thereof.
46+
47+
"Contribution" shall mean, as submitted to the Licensor for inclusion
48+
in the Work by the copyright owner or by an individual or Legal Entity
49+
authorized to submit on behalf of the copyright owner. For the purposes
50+
of this definition, "submitted" means any form of electronic, verbal,
51+
or written communication sent to the Licensor or its representations,
52+
including but not limited to communication on electronic mailing lists,
53+
source code control systems, and issue tracking systems that are managed
54+
by, or on behalf of, the Licensor for the purpose of discussing and
55+
improving the Work, but excluding communication that is conspicuously
56+
marked or designated in writing by the copyright owner as "Not a
57+
Contribution."
58+
59+
"Contributor" shall mean Licensor and any Legal Entity on behalf of
60+
whom a Contribution has been received by the Licensor and included
61+
within the Work.
62+
63+
2. Grant of Copyright License. Subject to the terms and conditions of
64+
this License, each Contributor hereby grants to You a perpetual,
65+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
66+
copyright license to reproduce, prepare Derivative Works of,
67+
publicly display, publicly perform, sublicense, and distribute the
68+
Work and such Derivative Works in Source or Object form.
69+
70+
3. Grant of Patent License. Subject to the terms and conditions of
71+
this License, each Contributor hereby grants to You a perpetual,
72+
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
73+
(except as stated in this section) patent license to make, have made,
74+
use, offer to sell, sell, import, and otherwise transfer the Work,
75+
where such license applies only to those patent claims licensable
76+
by such Contributor that are necessarily infringed by their
77+
Contribution(s) alone or by the combination of their Contribution(s)
78+
with the Work to which such Contribution(s) was submitted. If You
79+
institute patent litigation against any entity (including a cross-claim
80+
or counterclaim in a lawsuit) alleging that the Work or any Contribution
81+
embodied within the Work constitutes direct or contributory patent
82+
infringement, then any patent licenses granted to You under this License
83+
for that Work shall terminate as of the date such litigation is filed.
84+
85+
4. Redistribution. You may reproduce and distribute copies of the
86+
Work or Derivative Works thereof in any medium, with or without
87+
modifications, and in Source or Object form, provided that You
88+
meet the following conditions:
89+
90+
(a) You must give any other recipients of the Work or Derivative
91+
Works a copy of this License; and
92+
93+
(b) You must cause any modified files to carry prominent notices
94+
stating that You changed the files; and
95+
96+
(c) You must retain, in the Source form of any Derivative Works
97+
that You distribute, all copyright, patent, trademark, and
98+
attribution notices from the Source form of the Work,
99+
excluding those notices that do not pertain to any part of
100+
the Derivative Works; and
101+
102+
(d) If the Work includes a "NOTICE" text file as part of its
103+
distribution, You must include a readable copy of the
104+
attribution notices contained within such NOTICE file, in
105+
at least one of the following places: within a NOTICE text
106+
file distributed as part of the Derivative Works; within
107+
the Source form or documentation, if provided along with the
108+
Derivative Works; or, within a display generated by the
109+
Derivative Works, if and wherever such third-party notices
110+
normally appear. The contents of the NOTICE file are for
111+
informational purposes only and do not modify the License.
112+
You may add Your own attribution notices within Derivative
113+
Works that You distribute, alongside or in addition to the
114+
NOTICE text from the Work, provided that such additional
115+
attribution notices cannot be construed as modifying the License.
116+
117+
You may add Your own license statement for Your modifications and
118+
may provide additional grant of rights to use, reproduce, modify,
119+
prepare Derivative Works of, convert to other formats, and distribute
120+
the contributions, provided such additional grant of rights does not
121+
conflict with the terms and conditions of this License.
122+
123+
5. Submission of Contributions. Unless You explicitly state otherwise,
124+
any Contribution intentionally submitted for inclusion in the Work
125+
by You to the Licensor shall be under the terms and conditions of
126+
this License, without any additional terms or conditions.
127+
Notwithstanding the above, nothing herein shall supersede or modify
128+
the terms of any separate license agreement you may have executed
129+
with Licensor regarding such Contributions.
130+
131+
6. Trademarks. This License does not grant permission to use the trade
132+
names, trademarks, service marks, or product names of the Licensor,
133+
except as required for reasonable and customary use in describing the
134+
origin of the Work and reproducing the content of the NOTICE file.
135+
136+
7. Disclaimer of Warranty. Unless required by applicable law or
137+
agreed to in writing, Licensor provides the Work (and each
138+
Contributor provides its Contributions) on an "AS IS" BASIS,
139+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
140+
implied, including, without limitation, any warranties or conditions
141+
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
142+
PARTICULAR PURPOSE. You are solely responsible for determining the
143+
appropriateness of using or reproducing the Work and assume any
144+
risks associated with Your exercise of permissions under this License.
145+
146+
8. Limitation of Liability. In no event and under no legal theory,
147+
whether in tort (including negligence), contract, or otherwise,
148+
unless required by applicable law (such as deliberate and grossly
149+
negligent acts) or agreed to in writing, shall any Contributor be
150+
liable to You for damages, including any direct, indirect, special,
151+
incidental, or exemplary damages of any character arising as a
152+
result of this License or out of the use or inability to use the
153+
Work (including but not limited to damages for loss of goodwill,
154+
work stoppage, computer failure or malfunction, or all other
155+
commercial damages or losses), even if such Contributor has been
156+
advised of the possibility of such damages.
157+
158+
9. Accepting Warranty or Additional Liability. While redistributing
159+
the Work or Derivative Works thereof, You may choose to offer,
160+
and charge a fee for, acceptance of support, warranty, indemnity,
161+
or other liability obligations and/or rights consistent with this
162+
License. However, in accepting such obligations, You may offer such
163+
obligations only on Your own behalf and on Your sole responsibility,
164+
not on behalf of any other Contributor, and only if You agree to
165+
indemnify, defend, and hold each Contributor harmless for any
166+
liability incurred by, or claims asserted against, such Contributor
167+
by reason of your accepting any such warranty or additional liability.
168+
169+
END OF TERMS AND CONDITIONS
170+
171+
Copyright 2026 Node9 AI
172+
173+
Licensed under the Apache License, Version 2.0 (the "License");
174+
you may not use this file except in compliance with the License.
175+
You may obtain a copy of the License at
176+
177+
http://www.apache.org/licenses/LICENSE-2.0
178+
179+
Unless required by applicable law or agreed to in writing, software
180+
distributed under the License is distributed on an "AS IS" BASIS,
181+
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
182+
See the License for the specific language governing permissions and
183+
limitations under the License.

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@
4141
"hitl"
4242
],
4343
"author": "Nadav <nadav@node9.ai>",
44-
"license": "MIT",
44+
"license": "Apache-2.0",
4545
"files": [
4646
"dist",
4747
"README.md",

scripts/ai-review.mjs

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,8 +61,8 @@ ${truncatedDiff}`;
6161
console.log('Sending diff to Claude for review...');
6262
const client = new Anthropic({ apiKey: process.env.ANTHROPIC_API_KEY });
6363
const message = await client.messages.create({
64-
model: 'claude-sonnet-4-5',
65-
max_tokens: 1024,
64+
model: 'claude-sonnet-4-6',
65+
max_tokens: 2048,
6666
messages: [{ role: 'user', content: prompt }],
6767
});
6868

src/__tests__/core.test.ts

Lines changed: 95 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,6 +39,8 @@ import {
3939
getPersistentDecision,
4040
isDaemonRunning,
4141
evaluateSmartConditions,
42+
shouldSnapshot,
43+
DEFAULT_CONFIG,
4244
} from '../core.js';
4345

4446
// Global spies
@@ -742,6 +744,99 @@ describe('authorizeHeadless — smart rule hard block', () => {
742744
});
743745
});
744746

747+
// ── shouldSnapshot ────────────────────────────────────────────────────────────
748+
describe('shouldSnapshot', () => {
749+
const baseConfig = () => JSON.parse(JSON.stringify(DEFAULT_CONFIG)) as typeof DEFAULT_CONFIG;
750+
751+
it('returns true for a default snapshot tool', () => {
752+
const config = baseConfig();
753+
expect(shouldSnapshot('str_replace_based_edit_tool', { file_path: 'src/app.ts' }, config)).toBe(
754+
true
755+
);
756+
});
757+
758+
it('returns true for write_file with no path filters active', () => {
759+
const config = baseConfig();
760+
expect(shouldSnapshot('write_file', { file_path: 'src/index.ts' }, config)).toBe(true);
761+
});
762+
763+
it('returns false for a non-snapshot tool (bash)', () => {
764+
const config = baseConfig();
765+
expect(shouldSnapshot('bash', { command: 'ls' }, config)).toBe(false);
766+
});
767+
768+
it('returns false when enableUndo is false', () => {
769+
const config = baseConfig();
770+
config.settings.enableUndo = false;
771+
expect(shouldSnapshot('write_file', { file_path: 'src/app.ts' }, config)).toBe(false);
772+
});
773+
774+
it('respects ignorePaths — skips node_modules', () => {
775+
const config = baseConfig();
776+
expect(
777+
shouldSnapshot('write_file', { file_path: 'node_modules/lodash/index.js' }, config)
778+
).toBe(false);
779+
});
780+
781+
it('respects ignorePaths — skips dist/', () => {
782+
const config = baseConfig();
783+
expect(shouldSnapshot('edit_file', { file_path: 'dist/bundle.js' }, config)).toBe(false);
784+
});
785+
786+
it('respects ignorePaths — skips .log files', () => {
787+
const config = baseConfig();
788+
expect(shouldSnapshot('write_file', { file_path: 'logs/app.log' }, config)).toBe(false);
789+
});
790+
791+
it('allows src/ path that does not match any ignorePaths', () => {
792+
const config = baseConfig();
793+
expect(shouldSnapshot('edit', { file_path: 'src/utils/helper.ts' }, config)).toBe(true);
794+
});
795+
796+
it('respects onlyPaths — skips file outside onlyPaths when set', () => {
797+
const config = baseConfig();
798+
config.policy.snapshot.onlyPaths = ['src/**'];
799+
expect(shouldSnapshot('write_file', { file_path: 'scripts/deploy.sh' }, config)).toBe(false);
800+
});
801+
802+
it('respects onlyPaths — allows file inside onlyPaths', () => {
803+
const config = baseConfig();
804+
config.policy.snapshot.onlyPaths = ['src/**'];
805+
expect(shouldSnapshot('write_file', { file_path: 'src/api/routes.ts' }, config)).toBe(true);
806+
});
807+
808+
it('ignorePaths takes priority over onlyPaths', () => {
809+
const config = baseConfig();
810+
config.policy.snapshot.onlyPaths = ['src/**'];
811+
config.policy.snapshot.ignorePaths.push('src/generated/**');
812+
expect(shouldSnapshot('write_file', { file_path: 'src/generated/schema.ts' }, config)).toBe(
813+
false
814+
);
815+
});
816+
817+
it('handles args with path key instead of file_path', () => {
818+
const config = baseConfig();
819+
expect(shouldSnapshot('write_file', { path: 'src/app.ts' }, config)).toBe(true);
820+
});
821+
822+
it('handles args with filename key', () => {
823+
const config = baseConfig();
824+
expect(shouldSnapshot('write_file', { filename: 'src/app.ts' }, config)).toBe(true);
825+
});
826+
827+
it('allows snapshot when no file path present and no onlyPaths set', () => {
828+
const config = baseConfig();
829+
// No file_path — ignorePaths/onlyPaths checks are skipped
830+
expect(shouldSnapshot('write_file', {}, config)).toBe(true);
831+
});
832+
833+
it('user-added tool via config is snapshotted', () => {
834+
const config = baseConfig();
835+
config.policy.snapshot.tools.push('my_custom_write_tool');
836+
expect(shouldSnapshot('my_custom_write_tool', { file_path: 'src/foo.ts' }, config)).toBe(true);
837+
});
838+
});
839+
745840
describe('isDaemonRunning', () => {
746841
it('returns false when PID file does not exist', () => {
747842
// existsSpy returns false (set in beforeEach)

src/cli.ts

Lines changed: 6 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ import {
1212
getConfig,
1313
_resetConfigCache,
1414
explainPolicy,
15+
shouldSnapshot,
1516
} from './core';
1617
import { setupClaude, setupGemini, setupCursor } from './setup';
1718
import { startDaemon, stopDaemon, daemonStatus, DAEMON_PORT, DAEMON_HOST } from './daemon/index';
@@ -1045,19 +1046,7 @@ program
10451046
// Snapshot BEFORE the tool runs (PreToolUse) so undo can restore to
10461047
// the state prior to this change. Snapshotting after (PostToolUse)
10471048
// captures the changed state, making undo a no-op.
1048-
const STATE_CHANGING_TOOLS_PRE = [
1049-
'write_file',
1050-
'edit_file',
1051-
'edit',
1052-
'replace',
1053-
'terminal.execute',
1054-
'str_replace_based_edit_tool',
1055-
'create_file',
1056-
];
1057-
if (
1058-
config.settings.enableUndo &&
1059-
STATE_CHANGING_TOOLS_PRE.includes(toolName.toLowerCase())
1060-
) {
1049+
if (shouldSnapshot(toolName, toolInput, config)) {
10611050
await createShadowSnapshot(toolName, toolInput);
10621051
}
10631052

@@ -1186,16 +1175,10 @@ program
11861175
fs.appendFileSync(logPath, JSON.stringify(entry) + '\n');
11871176

11881177
const config = getConfig();
1189-
const STATE_CHANGING_TOOLS = [
1190-
'bash',
1191-
'shell',
1192-
'write_file',
1193-
'edit_file',
1194-
'replace',
1195-
'terminal.execute',
1196-
];
1197-
1198-
if (config.settings.enableUndo && STATE_CHANGING_TOOLS.includes(tool.toLowerCase())) {
1178+
1179+
// PostToolUse snapshot is a fallback for tools not covered by PreToolUse.
1180+
// Uses the same configurable snapshot policy.
1181+
if (shouldSnapshot(tool, {}, config)) {
11991182
await createShadowSnapshot();
12001183
}
12011184
} catch {

0 commit comments

Comments
 (0)