"""Local review prompts, not a Claude permission evaluator or security audit."""
import json,sys
from pathlib import Path
def review(obj):
    out=[]
    permissions=obj.get('permissions',{})
    for rule in permissions.get('allow',[]):
        if '*' in rule:
            out.append({'kind':'wildcard_allow','rule':rule,'question':'Which executable actions can this cover, including repository scripts?'})
    sandbox=obj.get('sandbox',{})
    for rule in sandbox.get('excludedCommands',[]):
        out.append({'kind':'sandbox_exclusion','rule':rule,'question':'Why does this command need to run outside the sandbox?'})
    if permissions.get('deny'):
        out.append({'kind':'deny_scope','question':'Command-text rules are not an OS boundary; check alternate invocation forms.'})
    return {'scope':'Static local JSON inspection only; no native enforcement tested','sandboxEnabledInInput':sandbox.get('enabled'), 'reviewItems':out,'itemCount':len(out)}
if __name__=='__main__':
    print(json.dumps(review(json.loads(Path(sys.argv[1] if len(sys.argv)>1 else 'permissions.example.json').read_text())),indent=2,sort_keys=True))
