- Home
- Skills
- Agents & Orchestration
- Repair Shell Argument & Quoting Bugs
More screenshots
Works with the AI tools you already use
Repair Shell Argument & Quoting Bugs
Repair Shell Argument & Quoting Bugs is a bounded ToolForge Labs workflow.
$8.99
Repair Shell Argument & Quoting Bugs
Example session with this skill installed
My Node.js script is failing to delete files with spaces in their names on Windows. It works on Mac. Here is the snippet: exec(rm -rf ${path}) where path comes from a user.
- Read your context and instructions
- Compiled the repair shell argument
I have analyzed the snippet. The issue stems from using a template literal with exec, which invokes a shell. On Windows, rm -rf is not a native command, and the shell (cmd.exe or PowerShell) handles spaces and quotes differently than POSIX shells. Furthermore, passing raw user input to a shell string is a command injection risk.
Diagnostic and Repair
The code currently relies on shell-level parsing, which fails when path contains spaces because the shell interprets the space as an argument delimiter. I recommend switching to execFile or spawn to pass arguments directly as an array, bypassing the shell's quoting logic entirely. This also resolves the security risk.
const { execFile } = require('child_process');
const path = require('path');
/**
* Repairs the file deletion logic to be cross-platform and space-safe.
* Uses direct argv passing instead of shell interpolation.
*/
function safeDelete(targetPath) {
// Map 'rm -rf' behavior to platform-specific commands if necessary,
// but better to use a library like 'fs-extra' or Node's 'fs.rmSync'.
// If we must use a subprocess:
const isWin = process.platform === 'win32';
if (isWin) {
// Windows: use 'rmdir' for directories or 'del' for files via cmd
// Or better, use the direct node fs API to avoid shell quirks
return execFile('cmd.exe', ['/c', 'rd', '/s', '/q', targetPath]);
} else {
// POSIX: pass targetPath as a single array element
return execFile('rm', ['-rf', targetPath]);
}
}
Deterministic Test Plan
To verify this fix, we use a local fixture with a complex filename:
const assert = require('assert');
const fs = require('fs');
// Test: Filename with spaces and special characters
const complexPath = './temp directory with "quotes" and spaces';
if (!fs.existsSync(complexPath)) fs.mkdirSync(complexPath);
safeDelete(complexPath, (err) => {
assert.strictEqual(err, null, 'Should delete path with spaces without error');
assert.strictEqual(fs.existsSync(complexPath), false, 'Path should be removed');
});
Next steps
- Replace all
exec()calls involving variables withexecFile()orspawn(). - Implement a path normalization step using
path.resolve()to ensure absolute paths are used. - Consider using
fs.rm(Node 14.14+) for a native, non-process approach to deletion.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Repair Shell Argument & Quoting Bugs is a bounded ToolForge Labs workflow. Diagnose and repair process invocation, argv construction, shell-vs-direct execution, quoting, escaping, spaces, Unicode, environment expansion, and platform command differences. Works from full repositories or partial context such as snippets, logs, configuration, traces, and architecture notes. Produces concrete repair patterns and focused deterministic tests while preserving existing product/security policy. It works from a full repository or partial evidence such as snippets, logs, configuration, traces, tickets, and architecture notes. The skill preserves existing product and security policy, separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair or review steps with focused deterministic validation or traceable evidence.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 27 days ago
- Passed all security checks, Safe to install