Command Execution
The rules that apply when the agent runs a shell command.
run_command never sees a raw shell string. Argv-only input, bare-command-name enforcement, and a parsed (not pattern-matched) sh -c script are the three layers — see the Sandbox page for the exact rules. Commands on the read-only allowlist (410 embedded entries, matched on the binary plus up to two arguments since v1.0.25: git status, docker ps, ls, ...) skip the confirm gate unless an argument is a sensitive path or the call sets network: true; everything else is gated by the active permission mode. Networking inside the sandbox is off unless the call sets network: true (v1.0.25).
The command policy is a denylist, not an allowlist: denied_command in config.json is the only list, and anything not on it runs subject to sandbox and confirmation. The former white_list / path_white_list keys are no longer read, and sensitive_map was renamed to sensitive_path — the daemon logs a warning if any of these keys is still present.