Bash(awk *) traded a single permission prompt for an unbounded write grant — awk writes files via print redirection, so the rule permitted arbitrary filesystem writes under the guise of a text-processing tool. Scripts that call awk internally are unaffected: permission rules match the top-level command string only, so make targets and ci/test.sh keep working. Only direct awk invocation now prompts. Shell glue needed more than once belongs in a named make target that can be allowlisted for what it actually does. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
70 lines
1.7 KiB
JSON
70 lines
1.7 KiB
JSON
{
|
|
"permissions": {
|
|
"allow": [
|
|
"Skill(pql)",
|
|
"Skill(clide)",
|
|
"Skill(whats-next)",
|
|
"Skill(git-commit)",
|
|
"Bash(git add *)",
|
|
"Bash(git commit *)",
|
|
"Bash(git status *)",
|
|
"Bash(git diff *)",
|
|
"Bash(git log *)",
|
|
"Bash(git show *)",
|
|
"Bash(git branch *)",
|
|
"Bash(git checkout *)",
|
|
"Bash(git switch *)",
|
|
"Bash(git merge *)",
|
|
"Bash(git rebase *)",
|
|
"Bash(git stash *)",
|
|
"Bash(git fetch *)",
|
|
"Bash(git pull *)",
|
|
"Bash(git push *)",
|
|
"Bash(git tag *)",
|
|
"Bash(git remote *)",
|
|
"Bash(git rev-parse *)",
|
|
"Bash(git symbolic-ref *)",
|
|
"Bash(git ls-remote *)",
|
|
"Bash(git config *)",
|
|
"Bash(git blame *)",
|
|
"Bash(git shortlog *)",
|
|
"Bash(git cherry-pick *)",
|
|
"Bash(dart *)",
|
|
"Bash(flutter *)",
|
|
"Bash(make *)",
|
|
"Bash(pql)",
|
|
"Bash(pql *)",
|
|
"Bash(clide)",
|
|
"Bash(clide *)"
|
|
],
|
|
"deny": [
|
|
"Edit(//var/mnt/data/projects/treesitter/**)",
|
|
"Write(//var/mnt/data/projects/treesitter/**)",
|
|
"Bash(rm -rf /*)",
|
|
"Bash(rm -rf ~*)",
|
|
"Bash(rm -rf $HOME*)",
|
|
"Bash(sudo rm *)",
|
|
"Bash(sudo chmod *)",
|
|
"Bash(sudo chown *)",
|
|
"Bash(mkfs*)",
|
|
"Bash(mkfs.*)",
|
|
"Bash(dd if=*)",
|
|
"Bash(git push --force*)",
|
|
"Bash(git push -f*)",
|
|
"Bash(git push --force-with-lease*)",
|
|
"Bash(git reset --hard*)",
|
|
"Bash(git clean -fd*)",
|
|
"Bash(git clean -fdx*)",
|
|
"Bash(git clean -ffd*)",
|
|
"Bash(git branch -D *)",
|
|
"Bash(git checkout -- *)",
|
|
"Bash(git restore .*)",
|
|
"Bash(chmod -R 777 *)",
|
|
"Bash(chmod 777 *)",
|
|
"Bash(git add -A*)",
|
|
"Bash(git add --all*)",
|
|
"Bash(git add .)"
|
|
]
|
|
}
|
|
}
|