Add the guard that confines each benchmark arm's agent to exactly one tool, so a result measures the tool rather than the agent's choice between tools. `guardCommand` inspects every binary a proposed shell command would reach — across pipelines, sequences, subshells, command and process substitutions, redirections, and leading environment assignments — and permits only the active arm's one allow-listed binary plus a curated set of harmless read-only utilities. Foreign binaries, absolute-path evasions (even of the arm's own binary), and interpreter-based fetch tricks are denied; the gitea-mcp arm runs with the shell disabled entirely. `provisionArmBin` produces a curated per-arm bin directory exposing only that arm's binary as the convenience layer behind the authoritative guard. Tests are colocated in bench/guard.test.ts and run via `npm run test:bench`.
10 KiB
10 KiB