mirror of
https://github.com/itme-brain/agent-team.git
synced 2026-05-08 10:40:12 -04:00
fix(settings): harden permission deny patterns for sensitive directories
- Replace command-specific Bash denies (cat/less) with broad glob patterns that catch any command referencing .ssh, .aws, .gnupg, .env - Add Write/Edit deny rules for ~/.ssh, ~/.aws, ~/.gnupg to prevent writes, not just reads
This commit is contained in:
parent
d99f89e5b2
commit
71dc65376a
1 changed files with 10 additions and 7 deletions
|
|
@ -22,13 +22,16 @@
|
|||
"Read(~/.gnupg/**)",
|
||||
"Read(./.env)",
|
||||
"Read(./.env.*)",
|
||||
"Bash(cat ~/.ssh/*)",
|
||||
"Bash(cat ~/.aws/*)",
|
||||
"Bash(cat ~/.gnupg/*)",
|
||||
"Bash(cat .env*)",
|
||||
"Bash(less ~/.ssh/*)",
|
||||
"Bash(less ~/.aws/*)",
|
||||
"Bash(less ~/.gnupg/*)"
|
||||
"Write(~/.ssh/**)",
|
||||
"Write(~/.aws/**)",
|
||||
"Write(~/.gnupg/**)",
|
||||
"Edit(~/.ssh/**)",
|
||||
"Edit(~/.aws/**)",
|
||||
"Edit(~/.gnupg/**)",
|
||||
"Bash(*.ssh/*)",
|
||||
"Bash(*.aws/*)",
|
||||
"Bash(*.gnupg/*)",
|
||||
"Bash(*.env*)"
|
||||
],
|
||||
"ask": [
|
||||
"Bash(rm *)",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue