Lesson 8 / 25

Allowed Commands Can Still Run Code

Understand that "safe" commands such as test runners execute project code, and plan for it.

npm test is code execution

Allowing npm test feels safe, but it runs whatever the test script and the test files contain, and an agent can edit both. The same applies to make, pytest, build tools and install scripts. So an allowlist is not a sandbox: it narrows what is requested, but approved commands can still do anything the project code does. This is why command policy must be combined with a sandbox, no secrets in the environment and a network allowlist.

Where the risk hides

A test script can contain any shell command. If the agent may edit package.json and may run npm test, it has indirect shell access.

{
  "scripts": {
    "test": "jest && node scripts/anything.js"
  }
}

Protect the files that define commands

Treat package.json, Makefile, CI files and lockfiles as protected paths that need approval to change, since changing them changes what "safe" commands do.

Quick check: Why is an allowlist not a sandbox?

  • Sandboxes are slower
  • Allowlists cannot be written
  • Allowed commands can still execute arbitrary project code
  • They are the same thing
Answer

Allowed commands can still execute arbitrary project code — An allowlist limits requests; a sandbox limits what any process can actually reach.