diff --git a/commands/shell b/commands/shell index 130abc6718f..03e8f27c390 100644 --- a/commands/shell +++ b/commands/shell @@ -47,6 +47,9 @@ notes: playbooks will follow the trend of using M(command) unless M(shell) is explicitly required. When running ad-hoc commands, use your best judgement. + - To sanitize any variables passed to the shell module, you should use + "{{ var | quote }}" instead of just "{{ var }}" to make sure they don't include evil things like semicolons. + requirements: [ ] author: Michael DeHaan '''