Shell

作者 pproencacf93c57cac89无许可证215 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7周前更新

Shell scripting best practices for writing safe, portable, and maintainable bash/sh scripts. Use when writing, reviewing, or refactoring shell scripts, Dockerfile RUN commands, Makefile recipes, CI pipeline scripts, cron jobs, or systemd ExecStart directives. Triggers on bash, sh, POSIX, ShellCheck, error handling, quoting, variables, set -euo pipefail.

AI 生成的概览

一份包含 49 条 shell 脚本最佳实践的参考指南,用于编写安全、可移植且易维护的 bash 与 sh 脚本。

功能
提供按优先级排列的 49 条规则,分为 9 个类别,涵盖安全与防护、可移植性、错误处理、变量、引号、函数、测试、性能与风格。每条规则都有独立的参考文件,包含说明以及错误与正确写法的对比示例。此外还提供完整汇编指南、章节定义以及新增规则的模板。
适用场景
适用于编写新的 bash 或 POSIX shell 脚本、审查脚本的安全漏洞、调试静默失败或行为异常的脚本、在 Linux、macOS 与容器之间移植脚本、优化脚本性能,以及搭建 CI/CD 流水线脚本时。
运行要求
无需脚本或运行时依赖,仅为纯说明性参考资料;需要阅读随附的 Markdown 参考文件。

Shell Scripts Best Practices (Community)

Comprehensive best practices guide for shell scripting, designed for AI agents and LLMs. Contains 49 rules across 9 categories, prioritized by impact from critical (safety, portability) to incremental (style). Each rule includes detailed explanations, real-world examples comparing incorrect vs. correct implementations, and specific impact metrics.

When to Apply

Reference these guidelines when:

  • Writing new bash or POSIX shell scripts
  • Reviewing shell scripts for security vulnerabilities
  • Debugging scripts that fail silently or behave unexpectedly
  • Porting scripts between Linux, macOS, and containers
  • Optimizing shell script performance
  • Setting up CI/CD pipelines with shell scripts

Rule Categories by Priority

PriorityCategoryImpactPrefixRules
1Safety & SecurityCRITICALsafety-6
2PortabilityCRITICALport-5
3Error HandlingHIGHerr-8
4Variables & DataHIGHvar-5
5Quoting & ExpansionMEDIUM-HIGHquote-6
6Functions & StructureMEDIUMfunc-5
7Testing & ConditionalsMEDIUMtest-5
8PerformanceLOW-MEDIUMperf-6
9Style & FormattingLOWstyle-3

Quick Reference

1. Safety & Security (CRITICAL)

  • safety-command-injection [blocked] - Prevent command injection from user input
  • safety-eval-avoidance [blocked] - Avoid eval for dynamic commands
  • safety-absolute-paths [blocked] - Use absolute paths for external commands
  • safety-temp-files [blocked] - Create secure temporary files
  • safety-suid-forbidden [blocked] - Never use SUID/SGID on shell scripts
  • safety-argument-injection [blocked] - Prevent argument injection with double dash

2. Portability (CRITICAL)

  • port-shebang-selection [blocked] - Choose shebang based on portability needs
  • port-avoid-bashisms [blocked] - Avoid bashisms in POSIX scripts
  • port-printf-over-echo [blocked] - Use printf instead of echo for portability
  • port-export-syntax [blocked] - Use portable export syntax
  • port-test-portability [blocked] - Use portable test constructs

3. Error Handling (HIGH)

  • err-strict-mode [blocked] - Use strict mode for error detection
  • err-exit-codes [blocked] - Use meaningful exit codes
  • err-trap-cleanup [blocked] - Use trap for cleanup on exit
  • err-stderr-messages [blocked] - Send error messages to stderr
  • err-pipefail [blocked] - Use pipefail to catch pipeline errors
  • err-check-commands [blocked] - Check command success explicitly
  • err-shellcheck [blocked] - Use ShellCheck for static analysis
  • err-debug-tracing [blocked] - Use debug tracing with set -x and PS4

4. Variables & Data (HIGH)

  • var-use-arrays [blocked] - Use arrays for lists instead of strings
  • var-local-scope [blocked] - Use local for function variables
  • var-naming-conventions [blocked] - Follow variable naming conventions
  • var-readonly-constants [blocked] - Use readonly for constants
  • var-default-values [blocked] - Use parameter expansion for defaults

5. Quoting & Expansion (MEDIUM-HIGH)

  • quote-always-quote-variables [blocked] - Always quote variable expansions
  • quote-dollar-at [blocked] - Use "$@" for argument passing
  • quote-command-substitution [blocked] - Quote command substitutions
  • quote-brace-expansion [blocked] - Use braces for variable clarity
  • quote-here-documents [blocked] - Use here documents for multi-line strings
  • quote-glob-safety [blocked] - Control glob expansion explicitly

6. Functions & Structure (MEDIUM)

  • func-main-pattern [blocked] - Use main() function pattern
  • func-single-purpose [blocked] - Write single-purpose functions
  • func-return-values [blocked] - Use return values correctly
  • func-documentation [blocked] - Document functions with header comments
  • func-avoid-aliases [blocked] - Prefer functions over aliases

7. Testing & Conditionals (MEDIUM)

  • test-double-brackets [blocked] - Use [[ ]] for tests in bash
  • test-arithmetic [blocked] - Use (( )) for arithmetic comparisons
  • test-explicit-empty [blocked] - Use explicit empty/non-empty string tests
  • test-file-operators [blocked] - Use correct file test operators
  • test-case-patterns [blocked] - Use case for pattern matching

8. Performance (LOW-MEDIUM)

  • perf-builtins-over-external [blocked] - Use builtins over external commands
  • perf-avoid-subshells [blocked] - Avoid unnecessary subshells
  • perf-process-substitution [blocked] - Use process substitution for temp files
  • perf-read-files [blocked] - Read files efficiently
  • perf-parameter-expansion [blocked] - Use parameter expansion for string operations
  • perf-batch-operations [blocked] - Batch operations instead of loops

9. Style & Formatting (LOW)

  • style-indentation [blocked] - Use consistent indentation
  • style-file-structure [blocked] - Follow consistent file structure
  • style-comments [blocked] - Write useful comments

How to Use

Read individual reference files for detailed explanations and code examples:

  • Section definitions [blocked] - Category structure and impact levels
  • Rule template [blocked] - Template for adding new rules

Reference Files

FileDescription
AGENTS.md [blocked]Complete compiled guide with all rules
references/_sections.md [blocked]Category definitions and ordering
assets/templates/_template.md [blocked]Template for new rules
metadata.json [blocked]Version and reference information

Key Sources

来源与署名

来源:pproenca/dot-skills位于skills/.experimental/shell提交cf93c57

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架