fix(cli): apply read-only bash and MCP to plan mode; propagate bash restrictions to sub-agents

This commit is contained in:
kirillk
2026-04-06 10:18:54 -04:00
parent 8816cb8358
commit 6011426160
2 changed files with 6 additions and 4 deletions
+2
View File
@@ -231,6 +231,8 @@ export namespace Agent {
PermissionNext.fromConfig({
question: "allow",
plan_exit: "allow",
bash: readOnlyBash, // kilocode_change: read-only bash for plan mode (mirrors ask agent)
...mcpRules, // kilocode_change: MCP with user approval for plan mode
external_directory: {
[path.join(Global.Path.data, "plans", "*")]: "allow",
},
+4 -4
View File
@@ -63,10 +63,10 @@ export const TaskTool = Tool.define("task", async (ctx) => {
const allowsTask = agent.permission.some((rule) => rule.permission === "task" && rule.action === "allow") // kilocode_change
// kilocode_change start — inherit edit restrictions from the calling agent so sub-agents
// cannot perform actions the parent agent is not allowed to perform.
// kilocode_change start — inherit edit and bash restrictions from the calling agent so
// sub-agents cannot perform actions the parent agent is not allowed to perform.
const caller = await Agent.get(ctx.agent)
const editRules = caller?.permission.filter((r) => r.permission === "edit") ?? []
const inherited = caller?.permission.filter((r) => r.permission === "edit" || r.permission === "bash") ?? []
// kilocode_change end
const session = await iife(async () => {
@@ -103,7 +103,7 @@ export const TaskTool = Tool.define("task", async (ctx) => {
action: "allow" as const,
permission: t,
})) ?? []),
...editRules, // kilocode_change — propagate caller's edit restrictions
...inherited, // kilocode_change — propagate caller's edit and bash restrictions
],
})
})