diff --git a/packages/opencode/src/agent/agent.ts b/packages/opencode/src/agent/agent.ts index 9055c646337..b88d031e2b6 100644 --- a/packages/opencode/src/agent/agent.ts +++ b/packages/opencode/src/agent/agent.ts @@ -231,6 +231,8 @@ export namespace Agent { PermissionNext.fromConfig({ question: "allow", plan_exit: "allow", + bash: readOnlyBash, // kilocode_change: read-only bash for plan mode (mirrors ask agent) + ...mcpRules, // kilocode_change: MCP with user approval for plan mode external_directory: { [path.join(Global.Path.data, "plans", "*")]: "allow", }, diff --git a/packages/opencode/src/tool/task.ts b/packages/opencode/src/tool/task.ts index a36b8715a2e..a8ab57cad04 100644 --- a/packages/opencode/src/tool/task.ts +++ b/packages/opencode/src/tool/task.ts @@ -63,10 +63,10 @@ export const TaskTool = Tool.define("task", async (ctx) => { const allowsTask = agent.permission.some((rule) => rule.permission === "task" && rule.action === "allow") // kilocode_change - // kilocode_change start — inherit edit restrictions from the calling agent so sub-agents - // cannot perform actions the parent agent is not allowed to perform. + // kilocode_change start — inherit edit and bash restrictions from the calling agent so + // sub-agents cannot perform actions the parent agent is not allowed to perform. const caller = await Agent.get(ctx.agent) - const editRules = caller?.permission.filter((r) => r.permission === "edit") ?? [] + const inherited = caller?.permission.filter((r) => r.permission === "edit" || r.permission === "bash") ?? [] // kilocode_change end const session = await iife(async () => { @@ -103,7 +103,7 @@ export const TaskTool = Tool.define("task", async (ctx) => { action: "allow" as const, permission: t, })) ?? []), - ...editRules, // kilocode_change — propagate caller's edit restrictions + ...inherited, // kilocode_change — propagate caller's edit and bash restrictions ], }) })