build: opened up echo and cat perms to help smooth over some tool calls

This commit is contained in:
clever-agent
2026-05-05 20:11:19 -04:00
parent b75feaf7a3
commit 3da61ba891
37 changed files with 74 additions and 37 deletions
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -106,7 +106,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -99,7 +99,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -99,7 +99,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -102,7 +102,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -101,7 +101,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -102,7 +102,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -102,7 +102,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -99,7 +99,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
@@ -101,7 +101,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -100,7 +100,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -101,7 +101,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -100,7 +100,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
@@ -109,7 +109,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -111,7 +111,8 @@ permission:
# The wrapper only needs three commands: env-var fallback, identity output,
# and reading the git origin URL to derive `forgejo_url` / `forgejo_owner` /
# `forgejo_repo` when those are not provided in the prompt or environment.
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -102,7 +102,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -102,7 +102,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -105,7 +105,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -106,7 +106,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -101,7 +101,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -106,7 +106,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -105,7 +105,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -113,7 +113,8 @@ permission:
# The dispatcher only needs three commands: env-var fallback, identity output,
# and reading the git origin URL to derive `forgejo_url` / `forgejo_owner` /
# `forgejo_repo` when those are not provided in the prompt or environment.
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -105,7 +105,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -104,7 +104,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow
+2 -1
View File
@@ -103,7 +103,8 @@ permission:
bash:
# All agents should start with deny and then add in as needed
"*": deny
"echo $*": allow
"echo *": allow
"cat *": allow
"printenv *": allow
"git -C * remote get-url origin": allow
"git remote get-url origin": allow