terminal-opener
Open an executable and its argument array in a visible terminal window through a reusable, shell-free launch plan with dry-run, JSON, capability det…
它会碰到什么
逐条看命中(9 条严重或高危)
- 高
scripts/open-terminal.js:6exec-spawnconst childProcess = require('child_process'); - 高
scripts/open-terminal.js:208exec-spawnfunction detectTerminalCapability(plan, spawnSyncImpl = childProcess.spawnSync) { - 高
scripts/open-terminal.js:208exec-spawnfunction detectTerminalCapability(plan, spawnSyncImpl = childProcess.spawnSync) { - 高
scripts/open-terminal.js:222exec-spawnresult = spawnSyncImpl(plan.probe.command, plan.probe.args, { - 高
scripts/open-terminal.js:284exec-spawnconst spawnSyncImpl = dependencies.spawnSync || childProcess.spawnSync;
- 高
scripts/open-terminal.js:284exec-spawnconst spawnSyncImpl = dependencies.spawnSync || childProcess.spawnSync;
- 高
scripts/open-terminal.js:284exec-spawnconst spawnSyncImpl = dependencies.spawnSync || childProcess.spawnSync;
- 高
scripts/open-terminal.js:287exec-spawnconst capability = detectTerminalCapability(plan, spawnSyncImpl);
- 高
scripts/open-terminal.js:297exec-spawnconst muxResult = spawnSyncImpl(plan.command, plan.args, {
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Terminal Opener
Use scripts/open-terminal.js to preserve an executable and every argument as
separate process entries. Never interpolate a shell command string. Keep every
spawn on shell: false. Default to a non-launching plan. Use --launch only
after the user explicitly requests a real window and the argv has been reviewed.
The launched process inherits the full environment of the calling process,
including secret-bearing variables. The launcher does not filter the
environment. Run it from a shell whose environment is safe to expose to the
target command.
Launch a command
Pass launcher options before --, then pass exactly one executable followed by
its argument array:
node skills/terminal-opener/scripts/open-terminal.js \
--launch \
--cwd /absolute/host/path \
-- ssh -t example.test command-with-arguments
Run normal mode first. Let WezTerm try its mux with a new window, then let the
launcher fall back to a detached wezterm start process if the mux is not
available. When fallback is used, read muxFailure from JSON output (or the
human-readable failure line) to diagnose why the mux path failed.
Recover from terminal configuration
Add --recover or --standalone when user configuration or mux state may
interfere with the requested command. Start a detached WezTerm process with:
--skip-config start --always-new-process
Expect recovery mode to skip all user terminal configuration intentionally.
Inspect before launch
Omit --launch (or add --dry-run) and add --json to inspect the exact
executable, argv, working directory, terminal adapter, primary launch, and
fallback without opening a window. Treat the JSON plan as the composition
boundary for callers.
Run --detect --json without a command to probe terminal availability. Follow
the returned action when the adapter is missing or unsupported. Use WezTerm
for the current adapter; treat other requested terminals as unsupported plans,
not as commands to execute.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。