It should be possible to configure a set of commands the agent can run without permission
- Linguagem predominante
- Shell
- Estrelas
- 11.2k
- Forks
- 1.9k
- Merge médio
- 14h 16min
- PRs com merge (30d)
- 6
Descrição
### Describe the feature or problem you'd like to solve
_No response_
### Proposed solution
Currently you can only set allow-all to allow the agent to execute commands without permission. Otherwise with every new session i have to approve every command over and over again.
The --allow-all flag bypasses all permission checks, which create real risks:
- Destructive commands like" rm-rf" could be e executed without confirmation
- Permission changes (chmod, chown) could silently alteer system security
A granular allowlist ( eg allow read, find, cat,ls but block rm, chmod, would provide a much better balance between autonomy and safety.
This should be configurable via instruction or agent files
### Example prompts or workflows
_No response_
### Additional context
_No response_
Guia de contribuição
Direção de pesquisa
Start by reviewing the existing --allow-all permission path and how instruction or agent files are configured. Define how a command allowlist coexists with confirmation and blocked commands, then verify that configured safe commands run without repeated approval while destructive commands still require permission.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- shell
- Domínio
- cli, security
- Tipo de issue
- Funcionalidade
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Status de atividade
- Pouca atividade
- Clareza
- Razoavelmente clara
- Facilidade para iniciantes
- 42/100