It should be possible to configure a set of commands the agent can run without permission
- Vorherrschende Sprache
- Shell
- Sterne
- 11.2k
- Forks
- 1.9k
- Ø Merge
- 14 Std. 16 Min.
- Gemergte PRs (30 T.)
- 6
Beschreibung
### Describe the feature or problem you'd like to solve
_No response_
### Proposed solution
Currently you can only set allow-all to allow the agent to execute commands without permission. Otherwise with every new session i have to approve every command over and over again.
The --allow-all flag bypasses all permission checks, which create real risks:
- Destructive commands like" rm-rf" could be e executed without confirmation
- Permission changes (chmod, chown) could silently alteer system security
A granular allowlist ( eg allow read, find, cat,ls but block rm, chmod, would provide a much better balance between autonomy and safety.
This should be configurable via instruction or agent files
### Example prompts or workflows
_No response_
### Additional context
_No response_
Beitragsleitfaden
Rechercherichtung
Start by reviewing the existing --allow-all permission path and how instruction or agent files are configured. Define how a command allowlist coexists with confirmation and blocked commands, then verify that configured safe commands run without repeated approval while destructive commands still require permission.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- shell
- Bereich
- cli, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Ruhig
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 42/100