Command injection ruleset

clearplane-command-injection combines converted command signatures with level-2 checks for shell separators, substitutions, server-side include execution syntax and exact Unix shell interpreter references.

Paranoia levels and compatibility

Shell documentation, command editors and template authoring can legitimately contain these constructs. Review level-2 findings before promotion. The upstream shell word list still has unresolved licensing and is not included; see third-party notices.

Start in Detection, review detections, and configure only the exclusions needed for the affected route and field.

See the measured coverage for the exact tested payload hashes, missed detections and false-positive rates. Ruleset operation explains activation, stages and rollback.