build: restricted bash to durther prevent force merges or sudo escalation
This commit is contained in:
@@ -119,7 +119,8 @@ permission:
|
||||
"*api/v1/repos/*/labels*": deny
|
||||
"*https://git.cleverthis.com/api/v1/repos/cleveragents/cleveragents-core/labels*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
|
||||
@@ -125,6 +125,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -123,6 +123,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -114,7 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -114,7 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -122,7 +122,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -113,7 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -124,6 +124,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -116,7 +116,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -113,7 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -113,7 +113,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -129,6 +129,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -114,7 +114,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -115,7 +115,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -129,6 +129,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -115,7 +115,8 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"sudo *": deny
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
@@ -126,6 +126,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -128,6 +128,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -118,6 +118,10 @@ permission:
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -127,6 +127,10 @@ permission:
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -121,6 +121,10 @@ permission:
|
||||
# CRITICAL: No direct HTTP calls to the OpenCode server
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -137,6 +137,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -118,6 +118,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
|
||||
@@ -118,6 +118,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
|
||||
@@ -118,6 +118,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
task:
|
||||
"*": deny
|
||||
"session-health-quick-util": allow
|
||||
|
||||
@@ -124,6 +124,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -137,6 +137,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -122,6 +122,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -130,6 +130,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# All the subagents you want this agent to have access to
|
||||
task:
|
||||
# All agents should start with deny and only enable what you need
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -120,6 +120,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -122,6 +122,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -120,6 +120,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -121,6 +121,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# target_agent is caller-controlled but is required by convention to be a
|
||||
# `task-*` agent (the final inner work agent in the tiered dispatch flow).
|
||||
# Restricting the wildcard to `task-*` enforces that contract while keeping
|
||||
|
||||
@@ -129,6 +129,9 @@ permission:
|
||||
"curl*localhost:4096*": deny
|
||||
"curl*127.0.0.1:4096*": deny
|
||||
|
||||
"*force_merge*": deny
|
||||
"*sudo*": deny
|
||||
|
||||
# No subagents needed
|
||||
task:
|
||||
"*": deny
|
||||
|
||||
Reference in New Issue
Block a user