Skip to content

feat(core): stop asking for external directory access by default - #53585

Merged
thdxr merged 3 commits into
v2from
default-permissions
Oct 6, 2026
Merged

thdxr merged 3 commits into
v2from
default-permissions

Conversation

@thdxr

@thdxr thdxr commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Issue for this PR

N/A

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Removes the external_directory: * → ask rule from the default agent ruleset in Agent.Info.default. The catch-all * → allow now covers paths outside the project too, so build/general/custom agents no longer prompt before touching them.

Explore also stops asking: it keeps its deny-by-default tool list but now explicitly allows external_directory.

Cleanup of rules that the new default makes redundant:

  • Agent no longer appends the managed external_directory allows (shell output, tool output, tmp, config) to every agent, and no longer depends on Global. User config rules are appended after these anyway, so they only ever applied when nothing else matched.
  • Plan drops its external_directory allow for the plan directory. Its edit restrictions (deny everywhere except the plan directory) are unchanged.

The .env read prompts stay as they are.

How did you verify your code works?

  • Added assertions to packages/core/test/agent.test.ts that an arbitrary outside path evaluates to allow for the build and explore agents.
  • The Plan plugin test now builds its fixture from Agent.Info.default instead of a hard-coded copy of the old ruleset, and checks that outside directories are allowed.
  • Updated packages/core/test/config/agent.test.ts expectations for the removed managed rules.
  • bun test in packages/core: all pass except isolates global home and XDG roots, which also fails on origin/v2 without this change. bun test in packages/cli passes.
  • bun run check passes.

Screenshots / recordings

N/A

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

— from 𝕺𝖕𝖊𝖓𝕮𝖔𝖉𝖊

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant