block-wildcard-agent-permissions
v0.0.6by open-coder-ai · author: chock-core
block-wildcard-agent-permissions is an Agent Plugin published by open-coder-ai. It packages 1 skill. We fetched the plugin.json from GitHub on 2026-10-02 and checked it against the official Agent Plugins 1.0.0 schema.
The mechanizable slice of excessive agency, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), agent permission grants that allow everything. A settings file whose shell grant or allow-list is a bare wildcard hands the agent unlimited tool authority for every future session, in a file reviewers rarely read as code. The agent-world twin of block-wildcard-iam: scope grants to what the task needs (e.g. Bash(git status:*)). The allow/alwaysAllow/tools/defaultMode keys match whether or not YAML-style config quotes them, word-bounded so "disallow"/"allowlist" are not mistaken for "allow". Escape: 'pragma: allowlist broad-agency' on the same line.
- Skills
- 1
- MCP servers
- 0
- Stars
- 8
- License
- Apache-2.0
- Repo created
- 2026-08-17
- Last pushed
- 2026-10-02
- Publisher type
- Organization
- Version
- 0.0.6
Links
Skills · 1
- block-wildcard-agent-permissions
- Pre-commit gate for the mechanizable slice of excessive agency: committed agent permission grants that allow everything. A settings file whose shell grant or allow-list is a bare wildcard hands the agent unlimited tool authority for every future session, in a file reviewers rarely read as code. The…
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
Category
Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
chock · policy-as-code · hook · block · asi03
Related by publisher and keywords
trigger: writing agent code or agent config, Python or TypeScript using AutoGen, CrewAI, LangChain, LangGraph, mem0, the OpenAI Agents or Claude Agent SDK, an MCP server or client (.mcp.json,.cursor/mcp.json,.vscode/mcp.json, claude_desktop_config.json,.codex/config.toml,.gemini/settings.json), docker-compose files for agents. avoid: code execution on the host, unpinned MCP servers and models, shell-reaching tools, approvals switched off, whole-environment and credential-store leaks, TLS verification off, unbounded loops, SQL and eval built from strings, stripped provenance markers. 29 rules in 10 packs, exec, supply, tools, approval, identity, comms, bounds, prompt-memory, code, provenance, each pack or rule allow|deny in.chock/agentic-security.json; bounds, prompt-memory and one supply rule start as allow.
Pre-commit gate for the mechanizable slice of ASI03: wildcard Action or Resource in IAM policy documents, AdministratorAccess attachment, GCP roles/owner or roles/editor, and Terraform wildcard action/resource lists. An agent's identity design stays with the advisory owasp-asi03 policy; this blocks the grants whose blast radius is everything. Escape: 'pragma: allowlist broad-privilege' on the same line, honoured at commit; also runs at agent tool-use, where it counts only when that exact line is already committed in HEAD.
The mechanizable slice of prompt-injection defense, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), invisible and direction-override Unicode. Bidi controls make code read differently than it parses (Trojan Source, CVE-2021-42574); Unicode tag-block characters smuggle instructions that are invisible to a human reviewer but fully legible to the agent reading the file. Zero-width joiners and bidi marks (ZWJ/ZWNJ/LRM/RLM) are deliberately NOT matched, they are legitimate in emoji sequences and in Persian, Arabic and Indic text, so ordinary internationalised content passes; only the override/embed/isolate controls and the tag block, which have no honest use in a source tree, are blocked. Escape: 'pragma: allowlist invisible-unicode' on the same line.
The mechanizable slice of CI supply-chain hardening, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), a workflow that references a third-party GitHub Action by a movable ref, a branch or a version tag, instead of a full 40-character commit SHA. A tag like v4 or a branch like main can be re-pointed at new code after review, so the action that runs tomorrow need not be the one that was audited today; a compromised or rug-pulled release rides in on exactly that mutability. The gate blocks an added line that references an action by a non-SHA ref (owner/repo at a tag/branch); a full 40-char SHA pin passes, local actions (no ref) pass, and 'pragma: allowlist unpinned-action' on the same line is a visible, deliberate exception. This is the OpenSSF Scorecard Pinned-Dependencies control for the slice a diff can show; signature and provenance verification stay out of scope.
Block direct commits and pushes to main or master. Enforced at commit time by reading the current branch, and at push time by parsing the refs the agent is pushing.
Blocks known credential patterns, vendor key prefixes, private-key blocks, and key/token/password assignments, at two enforcement points: at commit (the git hook, over staged changes) and at agent tool-use (the mcp-gateway / agent write guard, over a tool call's arguments), so a secret is caught as the agent writes it, before it ever reaches a commit. Matched by pattern, not by entropy analysis. Best-effort guard; not a replacement for a dedicated secret scanner.
[](https://agentpluginsdirectory.com/plugins/block-wildcard-agent-permissions)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.