Install
$ agentstack add skill-posidoni-shell-skill-shebang ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Shebang
The #! line picks a script's interpreter. Depth, mechanism, and citations in [reference/shebang.md](../../reference/shebang.md); runnable pairs in [examples/shebang/](../../examples/shebang/).
Rules at a glance
| Rule | Good | Bad | Caught by | |------|------|-----|-----------| | Prefer env for portable version | #!/usr/bin/env bash | #!/bin/bash | judgment | | Pass flags with env -S | #!/usr/bin/env -S bash -euo pipefail | #!/usr/bin/env bash -euo pipefail | SC2096 | | Absolute interpreter path | #!/usr/bin/env python3 | #!bin/python3 | SC2239 | | #! first, LF endings, no BOM | #!… on line 1 | #…, CRLF, blank line | SC1113/SC1017/SC1128 | | Executable scripts need a shebang | present | missing | SC2148 | | Keep the line < 127 bytes | short | long env -S chains | kernel (silent truncation) | | Pin absolute path when privileged | #!/bin/sh | #!/usr/bin/env (PATH-hijackable) | judgment | | Match the dialect you write | #!/usr/bin/env bash + bashisms | #!/bin/sh + [[ ]] | runtime (dash) |
Why the kernel forces these
The interpreter path is used verbatim (no PATH search, so it must be absolute), everything after it is a single argument (hence env -S for flags), and the line is length-limited and silently truncated past the kernel's buffer. See the reference for execve(2) details.
Do not
Polyglot/self-re-exec headers, ${ORIGIN}/-relative shebangs, arbitrary programs as interpreters, and relying on setuid — all fragile or non-standard.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: posidoni
- Source: posidoni/shell-skill
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.