feat(dangerous-mode): implement real-filesystem access with safety ch… (#276)

* feat(dangerous-mode): implement real-filesystem access with safety checks

- Introduced a 'dangerous mode' allowing the agent to operate on the real filesystem.
- Updated command validation to bypass path confinement while enforcing a blocklist for privileged commands.
- Added warnings and guidelines for users when operating in dangerous mode.
- Enhanced configuration to support dangerous mode and ensure it implies auto-approval.
- Updated tests to verify the behavior of commands and configurations in dangerous mode.

* feat(dangerous-mode): enhance logging and environment management for dangerous mode

* feat(dangerous-mode): improve handling of dangerous mode with environment flags and enhance test isolation
This commit is contained in:
Xi Zhang
2026-06-10 18:19:13 +01:00
committed by GitHub
parent fc05b5eed2
commit c02be519f6
16 changed files with 509 additions and 47 deletions
+10
View File
@@ -144,6 +144,16 @@ def deploy(
border_style="cyan",
)
)
if config.dangerous_mode:
from ..cli._constants import (
DANGEROUS_BANNER_LABEL,
DANGEROUS_BANNER_MESSAGE,
)
console.print(
f"[bold white on red] ⚠ {DANGEROUS_BANNER_LABEL} [/bold white on red] "
f"[bold red]{DANGEROUS_BANNER_MESSAGE}[/bold red]"
)
# 6. ccproxy lifecycle (only if any provider uses OAuth)
_ccproxy_proc = None