AGENTCFG-02: Coding Agent Pre-Approves Arbitrary Shell Commands
๐ด High ยท Coding-Agent Configuration
Detects committed allow lists that pre-approve any shell command (Bash, Bash(), Shell(), run_shell_command, a VS Code terminal auto-approve pattern matching everything) at high, and interpreter, network or authenticated-CLI commands with any arguments (Bash(curl:), Bash(python:), Bash(gh:*), โฆ) at medium. One level higher when the same list also pre-approves unrestricted file writes and web fetches. Deny lists are not treated as mitigation.
Detailsโ
| Field | Value |
|---|---|
| Rule ID | AGENTCFG-02 |
| Severity | High |
| Category | Coding-Agent Configuration |
Remediationโ
Pre-approve exact commands only (e.g. Bash(npm test), Bash(npm run lint)); never interpreters, curl/wget, package installers or cloud/Salesforce/GitHub CLIs with wildcards. Keep WebFetch and file writes behind a prompt.