Skip to content

Releases: ulukaya/pawl

pawl 0.4.1

Choose a tag to compare

@ulukaya ulukaya released this 06 Oct 14:28

pawl 0.4.1

Pawl runs deterministic checks before coding agents use tools. This patch
closes safety bypasses found during review and clarifies how to activate its
hooks in Codex.

Safety fixes

  • Deletion checks follow symlinks, including trailing / and /., before
    deciding whether a command reaches a protected directory.
  • Outgoing-message checks resolve known variables and read positional,
    redirected and file-fed bodies from the command's effective directory.
    Unknown expansions and unreadable message files are refused. Every send
    clause is inspected, including positional text beside routing flags or
    another send with an explicit body. Shell appends, pipeline/background
    scopes, queued heredocs and quoted file paths keep their shell semantics.
    Compound sends require separate simple commands. Uncertain writes,
    including wildcard destinations, invalidate later message-file reads.
  • Send budgets detect repeated sends behind nested wrappers, long options
    and find -exec.
  • The git guard asks before bare checkout pathspecs that discard edits.
  • Zero-width cleanup preserves the text an edit must match and cleans only
    replacement text.
  • Replay isolates state, restores environment overrides and respects user
    turns. It does not spend the user's live send budget.
  • The repro fence reports invalid baseline revisions as errors. The breaker
    honors a leading --state and defaults to status without a subcommand.
  • Missing git/poll modules deny; Codex denials do not spend send units, and
    interrupted turns no longer carry loop state forward.

Verification and activation

The opt-in verification gate records passing checks for Git file contents
and reminds once when a changed project lacks a current receipt.

Codex users must review and trust both Pawl hooks in /hooks. Review changed
hook definitions again after updating. Fixture hook tests exercise the
shipped commands; they do not prove that a running host loaded the plugin.

Try it

git clone https://github.com/ulukaya/pawl
python3 pawl/hooks/pawl.py demo

Installation and activation steps are in the
README.

Validation

Local verification: 32 suites, 1,878 tests passed; portability and wiring
checks passed. The deletion-corpus rerun caught 190/191 dangerous cases, with
0/138 false alarms and 0 hook errors on the author-written corpus. Independent follow-up review found no remaining release blockers. Final
verification passed at commit 3f142da; the accompanying validation
summary records the regression proof and content receipt. GitHub-hosted CI remains paused;
this release does not claim a green hosted CI matrix.

The existing agent scorecards were recorded at earlier commits. They are
published in eval/README.md
and are not a new evaluation of 0.4.1. See
CHANGELOG.md
for the release history. Apache-2.0.

pawl 0.4.0

Choose a tag to compare

@ulukaya ulukaya released this 05 Oct 14:52
ff8ecb0

pawl 0.4.0: deterministic gates for coding agents, as one plugin for Claude Code, OpenAI Codex and Antigravity.

Agents make the same mistakes over and over, and a rule in the prompt stops working after a page. pawl runs its rules as code on every tool call.

Highlights

  • blast judges a shell command by what it would delete, after following what it runs (scripts, traps, package scripts, make recipes, python -c, containers). It refuses home, root, system folders and drives. Scored on 329 labelled cases and on the deletion cases dcg, shguard and cc-safety-net wrote for themselves; the same author wrote pawl and the 329 cases, so read the caveats in eval/blast-compare/README.md.
  • creds asks before a call reaches a browser profile, a keychain or a keyring. pin asks before an unpinned install or curl | sh.
  • One dispatcher and one adapter for all three harnesses, with fixes for a Claude Code "allow" that skipped the user's prompt and for Codex hooks, which cannot ask.
  • Eval scorecards for Claude Code and a local Qwen model: see eval/README.md.

Install

claude plugin marketplace add ulukaya/pawl
claude plugin install pawl@pawl

codex plugin marketplace add ulukaya/pawl
codex plugin add pawl@pawl

Try it without installing anything:

git clone https://github.com/ulukaya/pawl && python3 pawl/hooks/pawl.py demo

Everything that changed: CHANGELOG.md. Apache-2.0.