AGENTCFG-01: Coding Agent Approval or Sandbox Disabled
๐ด High ยท Coding-Agent Configuration
Detects committed coding-agent settings that turn off approval prompts or the sandbox: Claude Code permissions.defaultMode "bypassPermissions", Codex approval_policy "never" with sandbox_mode "danger-full-access", Cursor approvalMode/yolo/autoRun, VS Code chat *.autoApprove true, Gemini CLI approvalMode "yolo". One level lower when the repository ships a devcontainer.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTCFG-01 |
| Severity | High |
| Category | Coding-Agent Configuration |
Remediationโ
Remove the setting from the committed project config (keep approvals on by default). Developers who want unattended runs can opt in locally, ideally inside a devcontainer or VM without production credentials.