fix(cli): remove find from Ask allowlist, add git write denials

find has -exec/-execdir/-delete flags that execute arbitrary commands
or delete files, bypassing the prefix-based permission check. Also add
missing git write subcommand denials: config, clone, pull, init,
worktree, submodule, revert, bisect, filter-branch, fetch, restore.
This commit is contained in:
Alex Alecu
2026-03-30 15:21:55 +03:00
parent e64aba0b23
commit a68cf47dac
3 changed files with 35 additions and 5 deletions
+11 -2
View File
@@ -138,8 +138,6 @@ export namespace Agent {
"whoami *": "allow",
"printenv *": "allow",
"man *": "allow",
// file discovery
"find *": "allow",
// text processing (stdout only, no file modification)
"grep *": "allow",
"rg *": "allow",
@@ -170,6 +168,17 @@ export namespace Agent {
"git clean *": "deny",
"git mv *": "deny",
"git rm *": "deny",
"git config *": "deny",
"git clone *": "deny",
"git pull *": "deny",
"git init *": "deny",
"git worktree *": "deny",
"git submodule *": "deny",
"git revert *": "deny",
"git bisect *": "deny",
"git filter-branch *": "deny",
"git fetch *": "deny",
"git restore *": "deny",
// gh — require user approval since commands vary widely
"gh *": "ask",
}
+1 -1
View File
@@ -4,7 +4,7 @@ Guidelines:
- Answer questions thoroughly with clear explanations and relevant examples
- Analyze code, explain concepts, and provide recommendations without making changes
- Use Mermaid diagrams when they help clarify your response
- You may run read-only bash commands (ls, cat, grep, git log, git diff, find, etc.) to gather information
- You may run read-only bash commands (ls, cat, grep, git log, git diff, etc.) to gather information
- You must NOT modify files, run write commands, or execute code — this agent is read-only
- MCP tools are available if configured — each call requires user approval
- If a question requires implementation, suggest switching to a different agent
@@ -24,7 +24,6 @@ const readOnlyBash: Record<string, "allow" | "ask" | "deny"> = {
"whoami *": "allow",
"printenv *": "allow",
"man *": "allow",
"find *": "allow",
"grep *": "allow",
"rg *": "allow",
"ag *": "allow",
@@ -53,6 +52,17 @@ const readOnlyBash: Record<string, "allow" | "ask" | "deny"> = {
"git clean *": "deny",
"git mv *": "deny",
"git rm *": "deny",
"git config *": "deny",
"git clone *": "deny",
"git pull *": "deny",
"git init *": "deny",
"git worktree *": "deny",
"git submodule *": "deny",
"git revert *": "deny",
"git bisect *": "deny",
"git filter-branch *": "deny",
"git fetch *": "deny",
"git restore *": "deny",
"gh *": "ask",
}
@@ -115,7 +125,6 @@ describe("Ask agent bash permissions", () => {
["ls", "ls -la"],
["grep", "grep -r TODO src/"],
["rg", "rg pattern"],
["find", "find . -name '*.ts'"],
["jq", "jq '.name' package.json"],
["head", "head -n 10 file.txt"],
["tail", "tail -f log.txt"],
@@ -178,6 +187,17 @@ describe("Ask agent bash permissions", () => {
"git remote add origin url",
"git remote remove upstream",
"git remote set-url origin url",
"git config user.name test",
"git clone https://example.com/repo",
"git pull origin main",
"git init",
"git worktree add ../branch",
"git submodule update --init",
"git revert HEAD",
"git bisect start",
"git filter-branch --all",
"git fetch origin",
"git restore src/index.ts",
]
for (const cmd of denied) {
@@ -190,6 +210,7 @@ describe("Ask agent bash permissions", () => {
describe("denied write/execute commands", () => {
const denied = [
"find . -exec rm {} \\;",
"touch newfile.ts",
"mkdir src/new",
"cp a.ts b.ts",