More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Repair Shell Argument & Quoting Bugs

    1

    Repair Shell Argument & Quoting Bugs is a bounded ToolForge Labs workflow.

    $8.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Repair Shell Argument & Quoting Bugs

    Repair Shell Argument & Quoting Bugs

    Example session with this skill installed

    My Node.js script is failing to delete files with spaces in their names on Windows. It works on Mac. Here is the snippet: exec(rm -rf ${path}) where path comes from a user.

    • Read your context and instructions
    • Compiled the repair shell argument

    I have analyzed the snippet. The issue stems from using a template literal with exec, which invokes a shell. On Windows, rm -rf is not a native command, and the shell (cmd.exe or PowerShell) handles spaces and quotes differently than POSIX shells. Furthermore, passing raw user input to a shell string is a command injection risk.

    Diagnostic and Repair

    The code currently relies on shell-level parsing, which fails when path contains spaces because the shell interprets the space as an argument delimiter. I recommend switching to execFile or spawn to pass arguments directly as an array, bypassing the shell's quoting logic entirely. This also resolves the security risk.

    const { execFile } = require('child_process');
    const path = require('path');
    
    /**
     * Repairs the file deletion logic to be cross-platform and space-safe.
     * Uses direct argv passing instead of shell interpolation.
     */
    function safeDelete(targetPath) {
      // Map 'rm -rf' behavior to platform-specific commands if necessary,
      // but better to use a library like 'fs-extra' or Node's 'fs.rmSync'.
      // If we must use a subprocess:
      const isWin = process.platform === 'win32';
      
      if (isWin) {
        // Windows: use 'rmdir' for directories or 'del' for files via cmd
        // Or better, use the direct node fs API to avoid shell quirks
        return execFile('cmd.exe', ['/c', 'rd', '/s', '/q', targetPath]);
      } else {
        // POSIX: pass targetPath as a single array element
        return execFile('rm', ['-rf', targetPath]);
      }
    }
    

    Deterministic Test Plan

    To verify this fix, we use a local fixture with a complex filename:

    const assert = require('assert');
    const fs = require('fs');
    
    // Test: Filename with spaces and special characters
    const complexPath = './temp directory with "quotes" and spaces';
    if (!fs.existsSync(complexPath)) fs.mkdirSync(complexPath);
    
    safeDelete(complexPath, (err) => {
      assert.strictEqual(err, null, 'Should delete path with spaces without error');
      assert.strictEqual(fs.existsSync(complexPath), false, 'Path should be removed');
    });
    

    Next steps

    1. Replace all exec() calls involving variables with execFile() or spawn().
    2. Implement a path normalization step using path.resolve() to ensure absolute paths are used.
    3. Consider using fs.rm (Node 14.14+) for a native, non-process approach to deletion.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Resolve cross-platform quoting differences between POSIX and Windows.Refactor unsafe shell interpolation into secure direct argv arrays.Debug environment expansion failures in CI/CD build scripts.Generate deterministic tests for complex command-line argument passing.

    About this skill

    Repair Shell Argument & Quoting Bugs is a bounded ToolForge Labs workflow. Diagnose and repair process invocation, argv construction, shell-vs-direct execution, quoting, escaping, spaces, Unicode, environment expansion, and platform command differences. Works from full repositories or partial context such as snippets, logs, configuration, traces, and architecture notes. Produces concrete repair patterns and focused deterministic tests while preserving existing product/security policy. It works from a full repository or partial evidence such as snippets, logs, configuration, traces, tickets, and architecture notes. The skill preserves existing product and security policy, separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair or review steps with focused deterministic validation or traceable evidence.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 27 days ago

    • Passed all security checks, Safe to install

    Listed27 days ago

    What's inside

    Frequently Asked Questions