# Command Execution

The rules that apply when the agent runs a shell command.

`run_command` never sees a raw shell string. Argv-only input, bare-command-name enforcement, and a parsed (not pattern-matched) `sh -c` script are the three layers — see the Sandbox page for the exact rules. Commands on the read-only allowlist (410 embedded entries, matched on the binary plus up to two arguments since v1.0.25: `git status`, `docker ps`, `ls`, ...) skip the confirm gate unless an argument is a sensitive path or the call sets `network: true`; everything else is gated by the active permission mode. Networking inside the sandbox is off unless the call sets `network: true` (v1.0.25).

The command policy is a **denylist**, not an allowlist: `denied_command` in `config.json` is the only list, and anything not on it runs subject to sandbox and confirmation. The former `white_list` / `path_white_list` keys are no longer read, and `sensitive_map` was renamed to `sensitive_path` — the daemon logs a warning if any of these keys is still present.
