An offline reader that explains a shell command stage by stage in plain English and flags what it will do to your machine — and never runs, fetches or simulates anything.
Someone says just paste this into your terminal. The line is long, it has a pipe in it, and the half you can read looks ordinary.
A one-liner is a flow chart flattened into a sentence. Caveat unflattens it: one box per stage, what each actually does, and which of them is the one running code nobody has read.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| Remote execution | a download piped straight into a shell |
| Destruction | rm -rf on a root-adjacent path, dd to a device |
| Obfuscation | base64 decoded into a shell, a long opaque blob |
| Permissions | chmod 777, recursive ownership changes |
| Transport | --insecure, disabled certificate checks |
| Elevation | which stage gets root, and what feeds it |
| Tracks | history wiping, log shredding |
Caveat reads the text of the command and nothing else. It cannot know what your aliases, functions or PATH will turn those words into, what a remote script will contain when it is fetched, or what your data is worth. ROUTINE is not permission — it means nothing matched.
git clone https://github.com/at0m-b0mb/Caveat-Shell-Reader.git
cd Caveat-Shell-Reader
python3 -m pip install -r requirements.txt
python3 -m caveat # the window
python3 -m caveat samples/ # the command line
python3 -m pytest -q # 1103 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.