Skip to content

Safety & Permissions ​

The Safety module detects dangerous commands before execution, and the Permission Manager controls which operations agents are allowed to perform.

Safety Detector ​

The SafetyDetector scans commands for 13 categories of destructive patterns:

typescript
import { SafetyDetector } from '@opensin/sdk'

const safety = new SafetyDetector()

safety.check('rm -rf /')
// { safe: false, reason: 'Destructive filesystem operation', pattern: 'rm-rf-root' }

safety.check('cat README.md')
// { safe: true }

Blocked Patterns ​

CategoryPatternExample
Filesystem destructionrm -rf /rm -rf /
Disk formattingmkfsmkfs.ext4 /dev/sda
Disk overwritedd of=/devdd if=/dev/zero of=/dev/sda
Fork bomb:(){ :|:& };:Shell fork bomb
World-writable rootchmod 777 /chmod -R 777 /
Destructive gitgit reset --hardgit reset --hard HEAD~10
Sudo removalsudo rmsudo rm -rf /var
Service shutdownshutdown, rebootshutdown -h now
Network interfaceifconfig downifconfig eth0 down
Firewall flushiptables -Fiptables -F
Password changepasswdpasswd root
Crontab clearcrontab -rcrontab -r
History clearhistory -chistory -c && history -w

Integration with Bash Tool ​

typescript
import { SafetyDetector } from '@opensin/sdk'

const safety = new SafetyDetector()

async function executeBash(command: string) {
  const check = safety.check(command)
  if (!check.safe) {
    return { error: `Blocked: ${check.reason}` }
  }
  // proceed with execFile...
}

Permission Manager ​

The PermissionManager controls agent access to files, directories, and operations:

typescript
import { PermissionManager } from '@opensin/sdk'

const permissions = new PermissionManager({
  mode: 'interactive',  // 'strict', 'permissive', 'interactive'
  allowlist: [
    '/workspace/src/**',
    '/workspace/tests/**',
    '/workspace/package.json',
  ],
  denylist: [
    '**/.env',
    '**/.env.*',
    '**/.git/config',
    '**/credentials*',
    '**/secrets*',
  ],
})

Permission Modes ​

ModeBehavior
strictOnly allowlisted paths, deny everything else
interactiveAsk user for confirmation on non-allowlisted paths
permissiveAllow everything except denylisted paths

Checking Permissions ​

typescript
const result = await permissions.check({
  tool: 'write',
  path: '/workspace/src/app.ts',
  action: 'modify',
})

if (result.allowed) {
  // proceed
} else if (result.needsConfirmation) {
  const confirmed = await askUser(`Allow write to ${result.path}?`)
  if (!confirmed) return { error: 'Denied by user' }
} else {
  return { error: `Permission denied: ${result.reason}` }
}

Tool-Level Permissions ​

Configure different permission levels per tool:

typescript
const permissions = new PermissionManager({
  toolPermissions: {
    'read': 'auto-approve',     // reading is always safe
    'write': 'confirm',         // writing needs confirmation
    'bash': 'confirm',          // shell commands need confirmation
    'edit': 'auto-approve',     // editing existing files is safe
    'glob': 'auto-approve',     // file search is safe
  },
})

Combining Safety + Permissions ​

Use both layers together for defense-in-depth:

typescript
const agent = new AgentLoop({
  model: 'claude-sonnet-4-6',
  tools: toolRegistry,
  safety: new SafetyDetector(),          // layer 1: block dangerous commands
  permissions: new PermissionManager({   // layer 2: control file access
    mode: 'interactive',
    denylist: ['**/.env', '**/secrets*'],
  }),
})

The safety detector runs first (blocking known destructive patterns), then the permission manager checks path-level access.


Relevante Mandate ​

MandatPriorityRegel
Bun-Only-1.5bun install / bun run statt npm
Annahmen-Verbot-5.0KEINE Diagnose ohne Beweis
Test-Beweis-Pflicht0.0KEIN "Done" ohne echten Test-Lauf

→ Alle Mandate

Guides and concepts for the OpenSIN API.