From 6011426160d1b263192d9ff62ddfe1ddbcf1a205 Mon Sep 17 00:00:00 2001 From: kirillk Date: Mon, 6 Apr 2026 10:18:54 -0400 Subject: [PATCH] fix(cli): apply read-only bash and MCP to plan mode; propagate bash restrictions to sub-agents --- packages/opencode/src/agent/agent.ts | 2 ++ packages/opencode/src/tool/task.ts | 8 ++++---- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/packages/opencode/src/agent/agent.ts b/packages/opencode/src/agent/agent.ts index 9055c646337..b88d031e2b6 100644 --- a/packages/opencode/src/agent/agent.ts +++ b/packages/opencode/src/agent/agent.ts @@ -231,6 +231,8 @@ export namespace Agent { PermissionNext.fromConfig({ question: "allow", plan_exit: "allow", + bash: readOnlyBash, // kilocode_change: read-only bash for plan mode (mirrors ask agent) + ...mcpRules, // kilocode_change: MCP with user approval for plan mode external_directory: { [path.join(Global.Path.data, "plans", "*")]: "allow", }, diff --git a/packages/opencode/src/tool/task.ts b/packages/opencode/src/tool/task.ts index a36b8715a2e..a8ab57cad04 100644 --- a/packages/opencode/src/tool/task.ts +++ b/packages/opencode/src/tool/task.ts @@ -63,10 +63,10 @@ export const TaskTool = Tool.define("task", async (ctx) => { const allowsTask = agent.permission.some((rule) => rule.permission === "task" && rule.action === "allow") // kilocode_change - // kilocode_change start — inherit edit restrictions from the calling agent so sub-agents - // cannot perform actions the parent agent is not allowed to perform. + // kilocode_change start — inherit edit and bash restrictions from the calling agent so + // sub-agents cannot perform actions the parent agent is not allowed to perform. const caller = await Agent.get(ctx.agent) - const editRules = caller?.permission.filter((r) => r.permission === "edit") ?? [] + const inherited = caller?.permission.filter((r) => r.permission === "edit" || r.permission === "bash") ?? [] // kilocode_change end const session = await iife(async () => { @@ -103,7 +103,7 @@ export const TaskTool = Tool.define("task", async (ctx) => { action: "allow" as const, permission: t, })) ?? []), - ...editRules, // kilocode_change — propagate caller's edit restrictions + ...inherited, // kilocode_change — propagate caller's edit and bash restrictions ], }) })