From 92e57fe2fe08c21bd42a4a4df33dfb08fd39211e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Sat, 7 Mar 2026 10:06:44 -0800 Subject: [PATCH 1/5] allow gh read operations --- modules/home/development.nix | 2 ++ 1 file changed, 2 insertions(+) diff --git a/modules/home/development.nix b/modules/home/development.nix index cc49a7bf..a7f55cc4 100644 --- a/modules/home/development.nix +++ b/modules/home/development.nix @@ -62,6 +62,8 @@ in { "Bash(git add *)" "Bash(git branch *)" "Bash(gh api:*)" + "Bash(gh search:*)" + "Bash(gh issue view*)" "Bash(mkdir *)" "Bash(journalctl:*)" "Bash(systemctl list-jobs:*)" From e7dc9341d03049c3158561c3e89fa9e92d2da603 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Sat, 7 Mar 2026 10:10:50 -0800 Subject: [PATCH 2/5] allow more gh read operations Co-Authored-By: Claude Opus 4.6 --- modules/home/development.nix | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/modules/home/development.nix b/modules/home/development.nix index a7f55cc4..9c8d2940 100644 --- a/modules/home/development.nix +++ b/modules/home/development.nix @@ -63,7 +63,19 @@ in { "Bash(git branch *)" "Bash(gh api:*)" "Bash(gh search:*)" + "Bash(gh issue list*)" + "Bash(gh issue status*)" "Bash(gh issue view*)" + "Bash(gh pr checks*)" + "Bash(gh pr diff*)" + "Bash(gh pr list*)" + "Bash(gh pr status*)" + "Bash(gh pr view*)" + "Bash(gh release list*)" + "Bash(gh release view*)" + "Bash(gh repo view*)" + "Bash(gh run list*)" + "Bash(gh run view*)" "Bash(mkdir *)" "Bash(journalctl:*)" "Bash(systemctl list-jobs:*)" From 38708e01762e09d58c4cad38cbdf7c7738aac2e7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Sat, 7 Mar 2026 10:13:19 -0800 Subject: [PATCH 3/5] expand pre-approved read permissions Add git (blame, remote, stash list, tag), graphite (log, ls, status), general CLI tools (jq, diff, curl, dig, file, du, sort, uniq, cut, tr, readlink, realpath, env, printenv, pwd, hostname, whoami, ping, nslookup), and organize permissions into labeled groups. Co-Authored-By: Claude Opus 4.6 --- modules/home/development.nix | 56 +++++++++++++++++++++++++++++------- 1 file changed, 45 insertions(+), 11 deletions(-) diff --git a/modules/home/development.nix b/modules/home/development.nix index 9c8d2940..3ee0a254 100644 --- a/modules/home/development.nix +++ b/modules/home/development.nix @@ -43,26 +43,54 @@ in { enabledMcpjsonServers = ["linear" "figma"]; permissions = { allow = [ - "Bash(find *)" + # File exploration + "Bash(cat *)" + "Bash(cut *)" + "Bash(diff *)" + "Bash(du *)" "Bash(echo *)" + "Bash(file *)" + "Bash(find *)" "Bash(grep *)" - "Bash(rg *)" "Bash(head *)" - "Bash(tail *)" - "Bash(cat *)" + "Bash(jq *)" "Bash(ls *)" + "Bash(readlink *)" + "Bash(realpath *)" + "Bash(rg *)" + "Bash(sort *)" + "Bash(tail *)" + "Bash(tr *)" + "Bash(uniq *)" "Bash(wc *)" "Bash(which *)" + # Environment + "Bash(env)" + "Bash(hostname)" + "Bash(printenv *)" + "Bash(pwd)" + "Bash(whoami)" + # Networking + "Bash(curl *)" + "Bash(dig *)" + "Bash(nslookup *)" + "Bash(ping -c *)" + # Nix "Bash(nix *)" "Bash(nix-eval-flake *)" - "Bash(git log *)" - "Bash(git diff *)" - "Bash(git status)" - "Bash(git show *)" + # Git "Bash(git add *)" + "Bash(git blame *)" "Bash(git branch *)" + "Bash(git diff *)" + "Bash(git log *)" + "Bash(git remote *)" + "Bash(git show *)" + "Bash(git stash list*)" + "Bash(git status)" + "Bash(git tag *)" + # GitHub CLI "Bash(gh api:*)" - "Bash(gh search:*)" "Bash(gh issue list*)" "Bash(gh issue status*)" "Bash(gh issue view*)" @@ -76,12 +104,18 @@ in { "Bash(gh repo view*)" "Bash(gh run list*)" "Bash(gh run view*)" - "Bash(mkdir *)" + "Bash(gh search:*)" + # Graphite + "Bash(gt log*)" + "Bash(gt ls*)" + "Bash(gt status*)" + # System "Bash(journalctl:*)" + "Bash(mkdir *)" "Bash(systemctl list-jobs:*)" "Bash(systemctl status:*)" - "Bash(* --version)" "Bash(* --help *)" + "Bash(* --version)" "WebFetch(domain:raw.githubusercontent.com)" "WebFetch(domain:github.com)" "WebSearch" From 25f07a935c6db67a231f11ec41e7fe243acd93f0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Sat, 7 Mar 2026 10:17:20 -0800 Subject: [PATCH 4/5] narrow permissions to reduce security risks - find: restrict to -name, -type, -path (no -exec) - curl: require -s/--silent prefix - nix: enumerate specific subcommands instead of wildcard (excludes nix run and nix shell) - git remote: read-only (-v, show) - git tag: read-only (-l, --list) - Remove * --help * and * --version wildcards (arbitrary command execution via leading wildcard) Co-Authored-By: Claude Opus 4.6 --- modules/home/development.nix | 29 ++++++++++++++++++++++------- 1 file changed, 22 insertions(+), 7 deletions(-) diff --git a/modules/home/development.nix b/modules/home/development.nix index 3ee0a254..381743a9 100644 --- a/modules/home/development.nix +++ b/modules/home/development.nix @@ -50,7 +50,9 @@ in { "Bash(du *)" "Bash(echo *)" "Bash(file *)" - "Bash(find *)" + "Bash(find * -name *)" + "Bash(find * -type *)" + "Bash(find * -path *)" "Bash(grep *)" "Bash(head *)" "Bash(jq *)" @@ -71,12 +73,25 @@ in { "Bash(pwd)" "Bash(whoami)" # Networking - "Bash(curl *)" + "Bash(curl -s *)" + "Bash(curl --silent *)" "Bash(dig *)" "Bash(nslookup *)" "Bash(ping -c *)" # Nix - "Bash(nix *)" + "Bash(nix build *)" + "Bash(nix develop *)" + "Bash(nix eval *)" + "Bash(nix flake *)" + "Bash(nix fmt *)" + "Bash(nix log *)" + "Bash(nix path-info *)" + "Bash(nix profile list*)" + "Bash(nix registry list*)" + "Bash(nix search *)" + "Bash(nix show-derivation *)" + "Bash(nix store *)" + "Bash(nix why-depends *)" "Bash(nix-eval-flake *)" # Git "Bash(git add *)" @@ -84,11 +99,13 @@ in { "Bash(git branch *)" "Bash(git diff *)" "Bash(git log *)" - "Bash(git remote *)" + "Bash(git remote -v*)" + "Bash(git remote show *)" "Bash(git show *)" "Bash(git stash list*)" "Bash(git status)" - "Bash(git tag *)" + "Bash(git tag -l *)" + "Bash(git tag --list *)" # GitHub CLI "Bash(gh api:*)" "Bash(gh issue list*)" @@ -114,8 +131,6 @@ in { "Bash(mkdir *)" "Bash(systemctl list-jobs:*)" "Bash(systemctl status:*)" - "Bash(* --help *)" - "Bash(* --version)" "WebFetch(domain:raw.githubusercontent.com)" "WebFetch(domain:github.com)" "WebSearch" From 965810814402f60ee74a53ebc7bf7c60e7ca6c98 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E2=9C=BF=20corey=20=28they/them=29?= Date: Sat, 7 Mar 2026 10:22:10 -0800 Subject: [PATCH 5/5] remove curl from pre-approved permissions Rely on domain-scoped WebFetch and gh api instead. curl can still be used with per-session approval. Co-Authored-By: Claude Opus 4.6 --- modules/home/development.nix | 2 -- 1 file changed, 2 deletions(-) diff --git a/modules/home/development.nix b/modules/home/development.nix index 381743a9..9fdc6c00 100644 --- a/modules/home/development.nix +++ b/modules/home/development.nix @@ -73,8 +73,6 @@ in { "Bash(pwd)" "Bash(whoami)" # Networking - "Bash(curl -s *)" - "Bash(curl --silent *)" "Bash(dig *)" "Bash(nslookup *)" "Bash(ping -c *)"