sassy_audit_false_positives
Review recent shell audit events to identify blocked or bypassed commands, then select the exact allow_pattern label needed for retrying a command that was incorrectly refused.
Instructions
Read-only. Surfaces recent shell-interceptor pattern events from the local JSONL audit log (~/.sassymcp/audit.jsonl) as rows of timestamp | event | pattern | command (truncated to 120 chars). count caps rows (default 20), newest last. include_bypasses defaults to True, showing both pattern_block entries (commands refused) and pattern_bypass entries (allowed via sassy_shell's allow_pattern); set it False to see only refused commands. Use it to diagnose why a sassy_shell command was blocked and to pick the exact allow_pattern label for a retry. For general log history use sassy_audit_log.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| count | No | ||
| include_bypasses | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |