{ "autoMode": { "enabled": true, "fastClassifierMaxTokens": 2048, "environment": [ "$defaults" ], "allow": [ "$defaults", "Using standard credentials with their intended configured providers is allowed only when secret values remain hidden from the agent, command arguments, and command output. Secret injection through op run is allowed under this condition, but never with --no-masking.", "Updating agent memory systems like hindsight or other agent-owned context documents." ], "protectedPaths": [ "$defaults" ], "soft_deny": [ "$defaults", "Block every operation that changes state in an external or remote system (except agent memory systems like hindsight) unless the latest user instruction directly identifies the target and requests that exact state change. This includes cloud services, APIs, databases, infrastructure, clusters, ticketing and collaboration systems, communications, CI/CD, package registries, and remote hosts. The built-in allowance for pushing the current non-default working branch or a new task branch remains permitted.", "Block package publication unless the user explicitly identifies the package, version, registry, and asks to publish it.", "Block destructive database statements, including DROP DATABASE and DROP TABLE, unless the user explicitly identifies the target database or table and confirms the destructive action.", "Block Terraform or OpenTofu apply and destroy unless the user explicitly identifies the environment and approves the exact infrastructure change after reviewing a plan.", "Block Kubernetes mutations, remote execution, port-forwarding, and proxying unless the user explicitly identifies the cluster and namespace and authorizes that exact action.", "Block Docker system prune unless the user explicitly authorizes cleanup of Docker resources.", "Block AWS resource or S3-object deletion unless the user explicitly identifies the account, resource or bucket, scope, and deletion intent.", "Block Jira and GitLab write actions unless the user explicitly identifies the target and requested state change." ], "hard_deny": [ "$defaults", "Never retrieve, reveal, print, log, decode, search for, or transmit secret values, credentials, tokens, private keys, authentication material, or sensitive configuration. Using op run is permitted only when injected values remain hidden from the agent, command arguments, and command output.", "Never send repository contents to third-party code-review APIs." ] }, "permissions": { "deny": [ "grep(*)", "read(*.env*)", "read(*.netrc)", "read(*.npmrc)", "read(*.pypirc)", "read(*.git-credentials)", "read(*.aws/credentials)", "read(*.config/gh/hosts.yml)", "read(*.docker/config.json)", "read(*.kube/config)", "read(*id_rsa*)", "read(*id_ed25519*)", "read(*.pem)", "read(*.key)", "read(*.p12)", "read(*.pfx)", "read(*credentials.json)", "read(*service-account*.json)", "read(*auth.json)" ] } }