Skip to main content

AGENTCFG-02: Coding Agent Pre-Approves Arbitrary Shell Commands

๐Ÿ”ด High ยท Coding-Agent Configuration

Detects committed allow lists that pre-approve any shell command (Bash, Bash(), Shell(), run_shell_command, a VS Code terminal auto-approve pattern matching everything) at high, and interpreter, network or authenticated-CLI commands with any arguments (Bash(curl:), Bash(python:), Bash(gh:*), โ€ฆ) at medium. One level higher when the same list also pre-approves unrestricted file writes and web fetches. Deny lists are not treated as mitigation.

Detailsโ€‹

FieldValue
Rule IDAGENTCFG-02
SeverityHigh
CategoryCoding-Agent Configuration

Remediationโ€‹

Pre-approve exact commands only (e.g. Bash(npm test), Bash(npm run lint)); never interpreters, curl/wget, package installers or cloud/Salesforce/GitHub CLIs with wildcards. Keep WebFetch and file writes behind a prompt.

See Alsoโ€‹