Skip to content

fix: Subagent permissions - #16

Open
webbrain-one wants to merge 1 commit into
assagman:mainfrom
webbrain-one:webbrain/issue-12
Open

webbrain-one wants to merge 1 commit into
assagman:mainfrom
webbrain-one:webbrain/issue-12

Conversation

@webbrain-one

Copy link
Copy Markdown

Closes #12

Respects tool restrictions defined in agent frontmatter.

Closes assagman#12
Copilot AI lite review requested due to automatic review settings August 12, 2026 11:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a permission-pattern matching utility intended to support restricting which MCP tools are visible/usable per agent (as requested in issue #12), by providing allow/deny glob-style filtering helpers for catalog tools.

Changes:

  • Added matchesPermission, isToolAllowed, and filterToolsByPermissions helpers for glob-style tool ID permission checks.
  • Re-exported the permission-filter helpers from the package entrypoint (src/index.ts).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
src/permission-filter.ts Introduces glob-based allow/deny evaluation and a catalog-tool filter helper.
src/index.ts Exposes the new permission-filter utilities to consumers via public exports.
Suppressed comments (1)

src/permission-filter.ts:48

  • Permission matching/precedence (deny over allow, wildcard behavior, exact match, default allow-all when allow list is empty) is core security behavior but currently has no unit tests. Add focused tests to prevent regressions, especially for patterns like context7*, *search, and mixed allow/deny lists.
export function isToolAllowed(toolId: string, permissions: PermissionPatterns): boolean {
  const { allow, deny } = permissions;

  // Check deny first - if denied, tool is not allowed
  if (deny && deny.length > 0) {

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/index.ts
// Provides on-demand access to MCP server tools through search and execute

export { ToolboxPlugin, ToolboxPlugin as default } from "./plugin";
export { filterToolsByPermissions, isToolAllowed } from "./permission-filter";
Comment thread src/permission-filter.ts
Comment on lines +3 to +9
/**
* Permission pattern format matching OpenCode agent frontmatter
*/
export interface PermissionPatterns {
allow?: string[];
deny?: string[];
}

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Subagent permissions

2 participants