Skip to main content

AGENTCFG-01: Coding Agent Approval or Sandbox Disabled

๐Ÿ”ด High ยท Coding-Agent Configuration

Detects committed coding-agent settings that turn off approval prompts or the sandbox: Claude Code permissions.defaultMode "bypassPermissions", Codex approval_policy "never" with sandbox_mode "danger-full-access", Cursor approvalMode/yolo/autoRun, VS Code chat *.autoApprove true, Gemini CLI approvalMode "yolo". One level lower when the repository ships a devcontainer.

Detailsโ€‹

FieldValue
Rule IDAGENTCFG-01
SeverityHigh
CategoryCoding-Agent Configuration

Remediationโ€‹

Remove the setting from the committed project config (keep approvals on by default). Developers who want unattended runs can opt in locally, ideally inside a devcontainer or VM without production credentials.

See Alsoโ€‹