Lesson 8 / 25
Allowed Commands Can Still Run Code
Understand that "safe" commands such as test runners execute project code, and plan for it.
npm test is code execution
Allowing npm test feels safe, but it runs whatever the test script and the test files contain, and an agent can edit both. The same applies to make, pytest, build tools and install scripts. So an allowlist is not a sandbox: it narrows what is requested, but approved commands can still do anything the project code does. This is why command policy must be combined with a sandbox, no secrets in the environment and a network allowlist.
Where the risk hides
A test script can contain any shell command. If the agent may edit package.json and may run npm test, it has indirect shell access.
{
"scripts": {
"test": "jest && node scripts/anything.js"
}
}Protect the files that define commands
Treat package.json, Makefile, CI files and lockfiles as protected paths that need approval to change, since changing them changes what "safe" commands do.
Quick check: Why is an allowlist not a sandbox?
- Sandboxes are slower
- Allowlists cannot be written
- Allowed commands can still execute arbitrary project code
- They are the same thing
Answer
Allowed commands can still execute arbitrary project code — An allowlist limits requests; a sandbox limits what any process can actually reach.