FunnyEnough

Engineering notes & expertise

Reading

Size
Theme
Motion
For long-form reading
Type
Width
Space
Aids

Audit a deny-list from the threat, not from the list

Governance auditModel-agnosticupdated 2026-08-28sha ec6ef37c6c32

Background →

Every deny-list is written by reading the deny-list. Someone adds a recursive delete, someone adds a history-rewriting push, and the list grows in the shape of what people already thought of. The holes are the commands nobody typed while writing it. The only way out is to stop reading the list and start from the danger, then come back and see what is missing.

Fill in: list_files threat verify_cmd

Shared as is, for reference. Read it and decide what it will do before you run it; using it is your responsibility, under the terms.