Hey, Does not this line mean if a user has defined a dummy function called shellescape() would be considered as a valid sanitizer ? https://github.com/github/codeql/blob/e02affd327603e89519b67ceffc7e60948831cc1/ruby/ql/lib/codeql/ruby/security/CommandInjectionCustomizations.qll#L53 Thank you