Skip to content

Permissions ​

What the agent's tools may run and reach. How these checks fit together is in Security.

Fields ​

FieldDescriptionDefault
EnabledToolsGlobally enabled tool names. Empty enables all tools[]
Security.BlacklistedPathsPaths file tools must not access; subpaths are also checked[]
Tools.File.RequireApprovalOutsideWorkspaceApprove file-tool access and shell launches outside workspace; false blocks themtrue
Tools.Shell.Policy.RulesPrefix rules checked before dangerous-operation and launch-directory checks; each entry is { "prefix": ["git", "push"], "decision": "allow" | "prompt" | "forbidden", "justification": "..." }. Every rule whose prefix matches applies and the most restrictive decision wins[]

Examples ​

Personal local hardening example:

json
{
  "Security": {
    "BlacklistedPaths": [
      "~/.ssh",
      "~/.gnupg",
      "~/.aws"
    ]
  },
  "Tools": {
    "File": {
      "RequireApprovalOutsideWorkspace": true
    },
    "Shell": {
      "Timeout": 300,
      "Policy": {
        "Rules": [
          { "prefix": ["git", "push"], "decision": "prompt", "justification": "pushes leave the machine" },
          { "prefix": ["rm"], "decision": "forbidden" }
        ]
      }
    }
  }
}

Rules learned from Always allow decisions are appended to .craft/security/shell-rules.json in the workspace data directory and take effect immediately.

Tool allow-list example:

json
{
  "EnabledTools": ["ReadFile", "GrepFiles", "WebSearch"]
}