a7aa814c42
#93392 was not just one pattern: every hardline rule with a bare \b anchor fired on its token anywhere in the command line, including inside quoted prose handed to echo, git commit -m, or gh --body. Anchor the command-name-token rules and quote-mask the positionless ones: - dd-to-block-device and kill -1 get the same _CMDPOS anchor as the format/rm/shutdown families, keeping their argument tails. - redirect-to-block-device and the fork bomb have no command-name token to anchor (`>` appears mid-command; the bomb is a function definition), so they now match a quote-masked variant (_mask_quoted_prose) where quoted string content is blanked. $() and backtick spans inside double quotes stay raw (the shell executes them), and any command whose command-position words include a shell carrier (sh/bash/zsh/ksh/dash -c, eval, source, .) is scanned unmasked -- quoting is not a bypass. bash/sh -c payloads also still surface as raw detection variants via _execution_flag_findings. Regression tests cover both directions for every touched pattern: quoted prose passes, and every true-positive shape (bare, ; && | separators, sudo/env prefix, $(), backticks, sh -c/bash -c/eval payloads) stays on the unconditional floor.