From a68cf47dacc02c3f91574c76f886feb543d198ee Mon Sep 17 00:00:00 2001 From: Alex Alecu Date: Mon, 30 Mar 2026 15:21:55 +0300 Subject: [PATCH] fix(cli): remove find from Ask allowlist, add git write denials find has -exec/-execdir/-delete flags that execute arbitrary commands or delete files, bypassing the prefix-based permission check. Also add missing git write subcommand denials: config, clone, pull, init, worktree, submodule, revert, bisect, filter-branch, fetch, restore. --- packages/opencode/src/agent/agent.ts | 13 ++++++++-- packages/opencode/src/agent/prompt/ask.txt | 2 +- .../kilocode/ask-agent-permissions.test.ts | 25 +++++++++++++++++-- 3 files changed, 35 insertions(+), 5 deletions(-) diff --git a/packages/opencode/src/agent/agent.ts b/packages/opencode/src/agent/agent.ts index 5590cc8abc4..fc99fd690ee 100644 --- a/packages/opencode/src/agent/agent.ts +++ b/packages/opencode/src/agent/agent.ts @@ -138,8 +138,6 @@ export namespace Agent { "whoami *": "allow", "printenv *": "allow", "man *": "allow", - // file discovery - "find *": "allow", // text processing (stdout only, no file modification) "grep *": "allow", "rg *": "allow", @@ -170,6 +168,17 @@ export namespace Agent { "git clean *": "deny", "git mv *": "deny", "git rm *": "deny", + "git config *": "deny", + "git clone *": "deny", + "git pull *": "deny", + "git init *": "deny", + "git worktree *": "deny", + "git submodule *": "deny", + "git revert *": "deny", + "git bisect *": "deny", + "git filter-branch *": "deny", + "git fetch *": "deny", + "git restore *": "deny", // gh — require user approval since commands vary widely "gh *": "ask", } diff --git a/packages/opencode/src/agent/prompt/ask.txt b/packages/opencode/src/agent/prompt/ask.txt index e324b0df985..40b5f9cf4aa 100644 --- a/packages/opencode/src/agent/prompt/ask.txt +++ b/packages/opencode/src/agent/prompt/ask.txt @@ -4,7 +4,7 @@ Guidelines: - Answer questions thoroughly with clear explanations and relevant examples - Analyze code, explain concepts, and provide recommendations without making changes - Use Mermaid diagrams when they help clarify your response -- You may run read-only bash commands (ls, cat, grep, git log, git diff, find, etc.) to gather information +- You may run read-only bash commands (ls, cat, grep, git log, git diff, etc.) to gather information - You must NOT modify files, run write commands, or execute code — this agent is read-only - MCP tools are available if configured — each call requires user approval - If a question requires implementation, suggest switching to a different agent diff --git a/packages/opencode/test/kilocode/ask-agent-permissions.test.ts b/packages/opencode/test/kilocode/ask-agent-permissions.test.ts index a727b014a00..50c31b1d116 100644 --- a/packages/opencode/test/kilocode/ask-agent-permissions.test.ts +++ b/packages/opencode/test/kilocode/ask-agent-permissions.test.ts @@ -24,7 +24,6 @@ const readOnlyBash: Record = { "whoami *": "allow", "printenv *": "allow", "man *": "allow", - "find *": "allow", "grep *": "allow", "rg *": "allow", "ag *": "allow", @@ -53,6 +52,17 @@ const readOnlyBash: Record = { "git clean *": "deny", "git mv *": "deny", "git rm *": "deny", + "git config *": "deny", + "git clone *": "deny", + "git pull *": "deny", + "git init *": "deny", + "git worktree *": "deny", + "git submodule *": "deny", + "git revert *": "deny", + "git bisect *": "deny", + "git filter-branch *": "deny", + "git fetch *": "deny", + "git restore *": "deny", "gh *": "ask", } @@ -115,7 +125,6 @@ describe("Ask agent bash permissions", () => { ["ls", "ls -la"], ["grep", "grep -r TODO src/"], ["rg", "rg pattern"], - ["find", "find . -name '*.ts'"], ["jq", "jq '.name' package.json"], ["head", "head -n 10 file.txt"], ["tail", "tail -f log.txt"], @@ -178,6 +187,17 @@ describe("Ask agent bash permissions", () => { "git remote add origin url", "git remote remove upstream", "git remote set-url origin url", + "git config user.name test", + "git clone https://example.com/repo", + "git pull origin main", + "git init", + "git worktree add ../branch", + "git submodule update --init", + "git revert HEAD", + "git bisect start", + "git filter-branch --all", + "git fetch origin", + "git restore src/index.ts", ] for (const cmd of denied) { @@ -190,6 +210,7 @@ describe("Ask agent bash permissions", () => { describe("denied write/execute commands", () => { const denied = [ + "find . -exec rm {} \\;", "touch newfile.ts", "mkdir src/new", "cp a.ts b.ts",