config.json Policies
Last updated
The policy keys in config.json that widen or narrow what tools may touch, and the keys that are no longer read.
Policy keys in config.json. The first two merge with values embedded in the binary (user entries add to, never replace, the defaults); the rest exist only as user config:
| Key | Embedded source | Purpose |
|---|---|---|
sensitive_path |
configs/jsons/sensitive_path.json |
Credential and key-material paths — reachable only after a password-backed per-session grant. Buckets: dirs, files, prefixes, extensions |
read_only_command |
configs/jsons/read_only_command.json |
run_command calls that skip the confirm gate (git status, ls, cat, ...). Since v1.0.25 an entry is matched against the binary plus at most its first two arguments (git config --get, docker compose ps), a call with network: true or a sensitive-path argument never matches, and the dedicated read-only command tool is gone |
denied_command |
— | Binaries run_command refuses outright, inside sh -c too |
denied_path |
— | Paths permanently off limits for reads and writes; no prompt can approve them. Entries must be absolute or start with ~/; the filesystem root is refused |
net_white_list |
— | Hosts exempt from the http_request SSRF guard |
Three keys are no longer read: sensitive_map (renamed sensitive_path), white_list (removed — commands run unless listed in denied_command), and path_white_list (removed — paths outside $HOME are approved per session). Up to v1.1.1 their presence logged a startup warning; v1.1.2 dropped the warning, so they are now ignored silently.
v0.35.0 dropped the last pre-v0.28.9 compatibility paths: limits.max_skill_iterations (superseded by limits.max_tool_iterations) and planner_model (superseded by dispatcher_model; up to v1.1.1 it was deleted from config.json on the next save, since v1.1.2 it is simply left in place) are no longer honoured, and the legacy api_tools/ / script_tools/ directories are no longer read — tools live under tools/api/ and tools/script/.