This explains a subtle shell pitfall: putting a tilde (~) into a quoted PATH entry does not expand to the home directory, so export PATH="$PATH:~/.local/bin/" leaves a literal "~/.local/bin/" entry that shells resolve as a ./~/ path in the current directory. The post shows how this happens because tilde expansion only runs on unquoted words (and in specific variable-assignment positions), demonstrates creating a ./~/.local/bin/kek executable that runs when PATH contains "~/.local/bin/", and highlights that sandboxing tools flagged such writable PATH entries as dangerous for that reason.
The practical takeaway is to replace ~ with $HOME in PATH assignments that are quoted (for example, export PATH="$PATH:$HOME/.local/bin/") since relying on unquoted tilde expansion or fragile whitespace-dependent behavior is unsafe. It gives quick checks to spot the problem (echo "$PATH" | tr ':' '\n' | grep '~') and advises fixing shell startup files (.bashrc/.zshrc/.profile). A sandbox tool discovered the issue and will get a clearer warning in a forthcoming patch.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.