The review of #210 found that the fix left the hole open and widened another. A command's words were cut on a space alone, while the verb's own splitter parts them on a space, a tab or a newline. The same line written with tabs found no space, so all of it was kept — the very hole this closes. Its words are now parted as the splitter parts them. And because the command arm sits above the arm that caps a string at 120 bytes, a command kept whole was no longer capped: for a 300-byte single token the change kept more than the code it replaced. The first word now carries the same cap. A one-word command is still kept whole, but the comment no longer claims it carries nothing to withhold: the record is written before the verb judges the line, so one word may be a token or compact JSON. The cap is what bounds that. The test now says the whole of what is kept for each line, which is also what proves the rest is gone, and looks for forbidden words as whole words rather than as substrings — so "set" is back in the list, and "show" cannot hide in a word such as "shown". All eight cases fail against the unfixed code.