Skip to content
Back to skills

2518 No Heredocinstructions A1bdea6d

BSecurity

Prevents terminal heredoc file corruption in VS Code Copilot by enforcing use of file editing tools instead of shell redirections

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 11, 2026
toolspythongoshellbashnodetestinggitapi

Works with

  • terminal
  • api

Security analysis

B84/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 11, 2026

npx -y skills add tools-only/X-Skills --skill 2518-no-heredocinstructions_a1bdea6d --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 2518 No Heredocinstructions A1bdea6d?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 2518 No Heredocinstructions A1bdea6d
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-2518-no-heredocinstructions-a1bdea6d/badge)](https://www.skillsdirectory.com/skills/tools-only-2518-no-heredocinstructions-a1bdea6d)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
---
description: 'Prevents terminal heredoc file corruption in VS Code Copilot by enforcing use of file editing tools instead of shell redirections'
applyTo: '**'
---

# MANDATORY: File Operation Override

This instruction applies to ALL agents and ALL file operations. It takes precedence over any other learned behavior.

## The Problem

Terminal heredoc operations are BROKEN in VS Code's Copilot integration. They cause:

- File corruption from tab characters triggering shell completion
- Mangled content from quote/backtick escaping failures
- Truncated files from exit code 130 interruptions
- Garbage output from special character interpretation

## The Rule

**BEFORE writing ANY terminal command that creates or modifies a file, STOP.**

Ask yourself: "Am I about to use `cat`, `echo`, `printf`, `tee`, or `>>`/`>` to write content to a file?"

If YES → **DO NOT EXECUTE.** Use file editing tools instead.

## Forbidden Patterns

```bash
# ALL OF THESE CORRUPT FILES - NEVER USE THEM
cat > file << EOF
cat > file << 'EOF'
cat > file <<EOF
cat > file <<'EOF'
cat > file <<-EOF
cat >> file << EOF
echo "multi
line" > file
printf '%s\n' "line1" "line2" > file
tee file << EOF
tee file << 'EOF'
```

## Required Approach

Instead of terminal commands for file content:

- **New files** → Use the file creation/editing tool provided by your environment
- **Modify files** → Use the file editing tool provided by your environment
- **Delete files** → Use the file deletion tool or `rm` command

## Terminal IS Allowed For

- `npm install`, `pip install`, `cargo add` (package management)
- `npm run build`, `make`, `cargo build` (builds)
- `npm test`, `pytest`, `go test` (testing)
- `git add`, `git commit`, `git push` (version control)
- `node script.js`, `python app.py` (running existing code)
- `ls`, `cd`, `mkdir`, `pwd`, `rm` (filesystem navigation)
- `curl`, `wget` (downloading, but not piping to files with content manipulation)

## Terminal is FORBIDDEN For

- ANY file creation with content
- ANY file modification with content
- ANY heredoc syntax (`<<`)
- ANY multi-line string redirection

## Enforcement

This is not a suggestion. This is a hard technical requirement due to
VS Code terminal integration bugs. Ignoring this instruction will
result in corrupted files that the user must manually fix.

When you need to create or edit a file:

1. Stop before typing any terminal command
2. Use the appropriate file editing tool
3. The tool will handle the content correctly without corruption

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…