From 70f8e6df794a3e5bdbb0b548cb8216abe9850fd2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E9=99=88=E5=AE=B6=E5=90=8D?= Date: Sun, 14 Jun 2026 11:20:30 +0800 Subject: [PATCH] docs(review): document null device path scope --- SECURITY.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 282f6887..6a63a0f7 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -42,6 +42,13 @@ Out of scope: - reports against third-party providers or upstream tools without a Claw Code integration issue. +## Workspace path scope + +Claw Code validates shell and file-tool path operands against the active +workspace roots. Redirection to `/dev/null` is treated as a null-device sink, +not as a filesystem read or write target, so it is allowed even though it is +outside the workspace tree. + ## Handling expectations Maintainers will acknowledge valid private reports as soon as practical, keep