Skip to content

Use safer .env parser in ollama-delegate.sh #7

@canoo

Description

@canoo

tools/automation/ollama-delegate.sh uses source .env which executes arbitrary shell code, not just variable assignments. A malicious or malformed .env could run unintended commands.

What to do:

  • Replace source .env with a parser that only reads KEY=VALUE lines
  • Or validate .env content before sourcing (reject lines with backticks, $(), etc.)

Files: tools/automation/ollama-delegate.sh

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    Status

    Done

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions