feat(dangerous-mode): implement real-filesystem access with safety ch… (#276)

* feat(dangerous-mode): implement real-filesystem access with safety checks

- Introduced a 'dangerous mode' allowing the agent to operate on the real filesystem.
- Updated command validation to bypass path confinement while enforcing a blocklist for privileged commands.
- Added warnings and guidelines for users when operating in dangerous mode.
- Enhanced configuration to support dangerous mode and ensure it implies auto-approval.
- Updated tests to verify the behavior of commands and configurations in dangerous mode.

* feat(dangerous-mode): enhance logging and environment management for dangerous mode

* feat(dangerous-mode): improve handling of dangerous mode with environment flags and enhance test isolation
This commit is contained in:
Xi Zhang
2026-06-10 18:19:13 +01:00
committed by GitHub
parent fc05b5eed2
commit c02be519f6
16 changed files with 509 additions and 47 deletions
+2
View File
@@ -29,6 +29,7 @@ def _make_config(
log_level: str = "warning",
langgraph_dev_jobs_per_worker: int = 10,
langgraph_dev_file_persistence: bool = True,
dangerous_mode: bool = False,
):
return SimpleNamespace(
default_workdir=default_workdir,
@@ -38,6 +39,7 @@ def _make_config(
log_level=log_level,
langgraph_dev_jobs_per_worker=langgraph_dev_jobs_per_worker,
langgraph_dev_file_persistence=langgraph_dev_file_persistence,
dangerous_mode=dangerous_mode,
)