# config.json Policies

The policy keys in `config.json` that widen or narrow what tools may touch, and the keys that are no longer read.

Policy keys in `config.json`. The first two merge with values embedded in the binary (user entries add to, never replace, the defaults); the rest exist only as user config:

| Key | Embedded source | Purpose |
|---|---|---|
| `sensitive_path` | `configs/jsons/sensitive_path.json` | Credential and key-material paths — reachable only after a password-backed per-session grant. Buckets: `dirs`, `files`, `prefixes`, `extensions` |
| `read_only_command` | `configs/jsons/read_only_command.json` | `run_command` calls that skip the confirm gate (`git status`, `ls`, `cat`, ...). Since v1.0.25 an entry is matched against the binary plus at most its first two arguments (`git config --get`, `docker compose ps`), a call with `network: true` or a sensitive-path argument never matches, and the dedicated read-only command tool is gone |
| `denied_command` | — | Binaries `run_command` refuses outright, inside `sh -c` too |
| `denied_path` | — | Paths permanently off limits for reads and writes; no prompt can approve them. Entries must be absolute or start with `~/`; the filesystem root is refused |
| `net_white_list` | — | Hosts exempt from the `http_request` SSRF guard |

Three keys are no longer read: `sensitive_map` (renamed `sensitive_path`), `white_list` (removed — commands run unless listed in `denied_command`), and `path_white_list` (removed — paths outside `$HOME` are approved per session). Up to v1.1.1 their presence logged a startup warning; v1.1.2 dropped the warning, so they are now ignored silently.

v0.35.0 dropped the last pre-v0.28.9 compatibility paths: `limits.max_skill_iterations` (superseded by `limits.max_tool_iterations`) and `planner_model` (superseded by `dispatcher_model`; up to v1.1.1 it was deleted from `config.json` on the next save, since v1.1.2 it is simply left in place) are no longer honoured, and the legacy `api_tools/` / `script_tools/` directories are no longer read — tools live under `tools/api/` and `tools/script/`.
