CommandCodeAI / CommandCodeAI/command-code
Sandbox requests (and/or use grading model, ...)
Chưa có ai nhận issue này.
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 4k
- Fork
- 350
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
Feature Description
Having a sandbox, or grading model for commands to automatically grade the safety of running it (or a combination of both) would be great.
A sandbox can see/limit what a command actually does and ask permission for things that need privileged access (commands interacting with the internet, touching files outside the working folder, ...).
An automated grading might make it easier for users to assess the danger of a command (this is done in GitHub Copilot, IIRC).
Use Case
Basically, I want a bit more ease of mind, less manual accepting every single tool call, less fatigue. At the same time, I don't want to use Shift + Tab to just blindly accept everything, as that might be potentially destructive or do unwanted modifications.
Additional Context
Having such a feature is a real game changer. I noticed this when switching to Codex from GitHub Copilot (in VS Code). In GitHub Copilot, the default mode is to ask for permission for almost every command ran. Codex is more intelligent with figuring out what to do, in general.
Also see a related issue for OpenCode: https://github.com/anomalyco/opencode/issues/2242.
BTW: I am on Windows, so having it work there as well would be a huge plus ;)
How important is this to you?
Blocking adoption or production use
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Hướng nghiên cứu
Không có tệp, bài kiểm thử hoặc điểm vào nào được nêu. Trước tiên, hãy xác định vị trí thực thi lệnh và xử lý quyền trong CLI, sau đó làm rõ liệu công việc hướng đến sandboxing, chấm điểm tự động hay cả hai, bao gồm hỗ trợ Windows và việc hoàn thành cần có nghĩa là gì.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Lĩnh vực
- cli, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 25/100