CAVEAT
read before you run

Read the command before you run it.

An offline reader that explains a shell command stage by stage in plain English and flags what it will do to your machine — and never runs, fetches or simulates anything.

Python 3.10+PyQt6 network never1103 testsMIT

Why

Someone says just paste this into your terminal. The line is long, it has a pipe in it, and the half you can read looks ordinary.

A one-liner is a flow chart flattened into a sentence. Caveat unflattens it: one box per stage, what each actually does, and which of them is the one running code nobody has read.

What it draws. The pipeline — a box per stage with its plain-English role, arrows for what flows between them, tinted by the worst finding, and a ROOT badge on any stage that runs elevated.
Caveat reading two samples

The reader on two of its bundled samples.

What it checks

SignalWhat trips it
Remote executiona download piped straight into a shell
Destructionrm -rf on a root-adjacent path, dd to a device
Obfuscationbase64 decoded into a shell, a long opaque blob
Permissionschmod 777, recursive ownership changes
Transport--insecure, disabled certificate checks
Elevationwhich stage gets root, and what feeds it
Trackshistory wiping, log shredding

The honest part

Caveat reads the text of the command and nothing else. It cannot know what your aliases, functions or PATH will turn those words into, what a remote script will contain when it is fetched, or what your data is worth. ROUTINE is not permission — it means nothing matched.

Install

git clone https://github.com/at0m-b0mb/Caveat-Shell-Reader.git
cd Caveat-Shell-Reader
python3 -m pip install -r requirements.txt

python3 -m caveat                      # the window
python3 -m caveat samples/             # the command line
python3 -m pytest -q                   # 1103 tests

The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.

One of seven readers