open-coder-ai avatar

block-wildcard-agent-permissions

v0.0.6

by open-coder-ai · author: chock-core

block-wildcard-agent-permissions is an Agent Plugin published by open-coder-ai. It packages 1 skill. We fetched the plugin.json from GitHub on 2026-10-02 and checked it against the official Agent Plugins 1.0.0 schema.

The mechanizable slice of excessive agency, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), agent permission grants that allow everything. A settings file whose shell grant or allow-list is a bare wildcard hands the agent unlimited tool authority for every future session, in a file reviewers rarely read as code. The agent-world twin of block-wildcard-iam: scope grants to what the task needs (e.g. Bash(git status:*)). The allow/alwaysAllow/tools/defaultMode keys match whether or not YAML-style config quotes them, word-bounded so "disallow"/"allowlist" are not mistaken for "allow". Escape: 'pragma: allowlist broad-agency' on the same line.

Skills
1
MCP servers
0
Stars
8
License
Apache-2.0
Repo created
2026-08-17
Last pushed
2026-10-02
Publisher type
Organization
Version
0.0.6

Links

Skills · 1

block-wildcard-agent-permissions
Pre-commit gate for the mechanizable slice of excessive agency: committed agent permission grants that allow everything. A settings file whose shell grant or allow-list is a bare wildcard hands the agent unlimited tool authority for every future session, in a file reviewers rarely read as code. The…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

Category

Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.

Keywords

chock · policy-as-code · hook · block · asi03

Related by publisher and keywords

  • trigger: writing agent code or agent config, Python or TypeScript using AutoGen, CrewAI, LangChain, LangGraph, mem0, the OpenAI Agents or Claude Agent SDK, an MCP server or client (.mcp.json,.cursor/mcp.json,.vscode/mcp.json, claude_desktop_config.json,.codex/config.toml,.gemini/settings.json), docker-compose files for agents. avoid: code execution on the host, unpinned MCP servers and models, shell-reaching tools, approvals switched off, whole-environment and credential-store leaks, TLS verification off, unbounded loops, SQL and eval built from strings, stripped provenance markers. 29 rules in 10 packs, exec, supply, tools, approval, identity, comms, bounds, prompt-memory, code, provenance, each pack or rule allow|deny in.chock/agentic-security.json; bounds, prompt-memory and one supply rule start as allow.

  • block-wildcard-iamopen-coder-ai

    Pre-commit gate for the mechanizable slice of ASI03: wildcard Action or Resource in IAM policy documents, AdministratorAccess attachment, GCP roles/owner or roles/editor, and Terraform wildcard action/resource lists. An agent's identity design stays with the advisory owasp-asi03 policy; this blocks the grants whose blast radius is everything. Escape: 'pragma: allowlist broad-privilege' on the same line, honoured at commit; also runs at agent tool-use, where it counts only when that exact line is already committed in HEAD.

  • The mechanizable slice of prompt-injection defense, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), invisible and direction-override Unicode. Bidi controls make code read differently than it parses (Trojan Source, CVE-2021-42574); Unicode tag-block characters smuggle instructions that are invisible to a human reviewer but fully legible to the agent reading the file. Zero-width joiners and bidi marks (ZWJ/ZWNJ/LRM/RLM) are deliberately NOT matched, they are legitimate in emoji sequences and in Persian, Arabic and Indic text, so ordinary internationalised content passes; only the override/embed/isolate controls and the tag block, which have no honest use in a source tree, are blocked. Escape: 'pragma: allowlist invisible-unicode' on the same line.

  • pin-github-actionsopen-coder-ai

    The mechanizable slice of CI supply-chain hardening, enforced at two points: at commit (the git hook, over staged changes) and at agent tool-use (over a tool call's arguments, as the agent writes), a workflow that references a third-party GitHub Action by a movable ref, a branch or a version tag, instead of a full 40-character commit SHA. A tag like v4 or a branch like main can be re-pointed at new code after review, so the action that runs tomorrow need not be the one that was audited today; a compromised or rug-pulled release rides in on exactly that mutability. The gate blocks an added line that references an action by a non-SHA ref (owner/repo at a tag/branch); a full 40-char SHA pin passes, local actions (no ref) pass, and 'pragma: allowlist unpinned-action' on the same line is a visible, deliberate exception. This is the OpenSSF Scorecard Pinned-Dependencies control for the slice a diff can show; signature and provenance verification stay out of scope.

  • protect-main-branchopen-coder-ai

    Block direct commits and pushes to main or master. Enforced at commit time by reading the current branch, and at push time by parsing the refs the agent is pushing.

  • scan-secretsopen-coder-ai

    Blocks known credential patterns, vendor key prefixes, private-key blocks, and key/token/password assignments, at two enforcement points: at commit (the git hook, over staged changes) and at agent tool-use (the mcp-gateway / agent write guard, over a tool call's arguments), so a secret is caught as the agent writes it, before it ever reaches a commit. Matched by pattern, not by entropy analysis. Best-effort guard; not a replacement for a dedicated secret scanner.

Add the verified badge to your README[![Verified by AgentPluginsDirectory.com against Schema 1.0.0](https://agentpluginsdirectory.com/badge.svg)](https://agentpluginsdirectory.com/plugins/block-wildcard-agent-permissions)

✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.