Unsafe tools (shell, background processes) gated behind explicit permission #24
Labels
No labels
bug
commercial
documentation
duplicate
enhancement
feature
good first issue
help wanted
invalid
question
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
jasoncouture/llama-shears#24
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Shell execution and background-process tools — gated behind explicit permission (per-agent, per-call, or both). The kind of capability that's amazing when it's wanted and catastrophic when an agent reaches for it without authorization.
Depends on the tool security model (#23).
Tracked in TASKS.md.
Tool metadata was updated to surface the various metadata hints, which will enable this.
Additionally, a tool security model was added recently, and #23 ( Completed in #109 ) is done.
The hints currently surfaced from MCP to the internal representation are:
readOnlyHintdestructiveHintidempotentHintopenWorldHint