CommandCodeAI / CommandCodeAI/command-code

Sandbox requests (and/or use grading model, ...)

Đang mở
#467 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

windows
Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
4k
Fork
350
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

Feature Description

Having a sandbox, or grading model for commands to automatically grade the safety of running it (or a combination of both) would be great.

A sandbox can see/limit what a command actually does and ask permission for things that need privileged access (commands interacting with the internet, touching files outside the working folder, ...).

An automated grading might make it easier for users to assess the danger of a command (this is done in GitHub Copilot, IIRC).

Use Case

Basically, I want a bit more ease of mind, less manual accepting every single tool call, less fatigue. At the same time, I don't want to use Shift + Tab to just blindly accept everything, as that might be potentially destructive or do unwanted modifications.

Additional Context

Having such a feature is a real game changer. I noticed this when switching to Codex from GitHub Copilot (in VS Code). In GitHub Copilot, the default mode is to ask for permission for almost every command ran. Codex is more intelligent with figuring out what to do, in general.

Also see a related issue for OpenCode: https://github.com/anomalyco/opencode/issues/2242.

BTW: I am on Windows, so having it work there as well would be a huge plus ;)

How important is this to you?

Blocking adoption or production use

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Không có tệp, bài kiểm thử hoặc điểm vào nào được nêu. Trước tiên, hãy xác định vị trí thực thi lệnh và xử lý quyền trong CLI, sau đó làm rõ liệu công việc hướng đến sandboxing, chấm điểm tự động hay cả hai, bao gồm hỗ trợ Windows và việc hoàn thành cần có nghĩa là gì.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
cli, security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.