shareAI-lab / shareAI-lab/learn-claude-code
s03_permission: Agent bypasses workspace validation through bash
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 12.4k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 6
Description
When file operations (read_file, write_file, edit_file) access paths outside WORKDIR, the permission check correctly returns:
Path escapes workspace
However, the agent bypasses the restriction by switching to the bash tool to directly access files outside the workspace.
The current permission mechanism only validates individual file tools and does not prevent equivalent operations through other tools.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing permission checks for read_file, write_file, edit_file, and the bash tool, focusing on how WORKDIR boundaries are enforced. Verify that equivalent bash file operations cannot escape WORKDIR, then exercise both the file tools and bash path cases to confirm the restriction is consistent.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- cli, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100