4 ms·
No. I haven't approved commands in more than a year. Worst that I've seen was some agent running git checkout -- in a repo with uncommitted changes. Annoying, b
by glerk 2mo ago
No. I haven't approved commands in more than a year. Worst that I've seen was some agent running git checkout -- in a repo with uncommitted changes. Annoying, but not catastrophic.
Imo these explicit tool-level permissions are really just a bandaid for bad sandboxing. Just be aware of where you are running your agent and what data is at risk of being destroyed or compromised. Assume that arbitrary code can run at any time and be prepared to recover from that.
- imtringued 2mo agoI struggle to see the difference between sandboxing and only allowing access to specific executables (not bash for starters) with an approval rule for the arguments.
- glerk 2mo agoMainly ergonomics. Deriving all these approval rules is a pain and you're likely to miss something. > not bash for starters you'll end up either severely limiting what your agent can do or force it into finding some inefficient workarounds (they can be very creative...)