It should be possible to configure a set of commands the agent can run without permission
- 主要语言
- Shell
- 星标
- 11.2k
- 派生
- 1.9k
- 平均合并
- 14 小时 16 分钟
- 30 天内合并 PR
- 6
描述
### Describe the feature or problem you'd like to solve
_No response_
### Proposed solution
Currently you can only set allow-all to allow the agent to execute commands without permission. Otherwise with every new session i have to approve every command over and over again.
The --allow-all flag bypasses all permission checks, which create real risks:
- Destructive commands like" rm-rf" could be e executed without confirmation
- Permission changes (chmod, chown) could silently alteer system security
A granular allowlist ( eg allow read, find, cat,ls but block rm, chmod, would provide a much better balance between autonomy and safety.
This should be configurable via instruction or agent files
### Example prompts or workflows
_No response_
### Additional context
_No response_
贡献指南
调研方向
Start by reviewing the existing --allow-all permission path and how instruction or agent files are configured. Define how a command allowlist coexists with confirmation and blocked commands, then verify that configured safe commands run without repeated approval while destructive commands still require permission.
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- shell
- 领域
- cli, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 42/100