ReadonlyidShort identifier for the rule (e.g. 'nested-param-expansion').
ReadonlydescriptionHuman-readable description of what this rule detects.
ReadonlypatternRegex that detects the forbidden pattern in shell code.
ReadonlyrationaleExplanation of why this pattern is dangerous in sandboxed execution.
A shell safety rule with a human-readable name, detection regex, and explanation of why it's forbidden.