# Allowed Commands Can Still Run Code — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/perm-allowed-can-run-code

> Understand that "safe" commands such as test runners execute project code, and plan for it.

## npm test is code execution

Allowing `npm test` feels safe, but it runs whatever the `test` script and the test files contain, and an agent can edit both. The same applies to `make`, `pytest`, build tools and install scripts. So an allowlist is **not a sandbox**: it narrows what is requested, but approved commands can still do anything the project code does. This is why command policy must be combined with a sandbox, no secrets in the environment and a network allowlist.

## Where the risk hides

A test script can contain any shell command. If the agent may edit `package.json` and may run `npm test`, it has indirect shell access.

```json
{
  "scripts": {
    "test": "jest && node scripts/anything.js"
  }
}
```

## Protect the files that define commands

Treat `package.json`, `Makefile`, CI files and lockfiles as protected paths that need approval to change, since changing them changes what "safe" commands do.

**Quiz:** Why is an allowlist not a sandbox?

- [ ] Sandboxes are slower
- [ ] Allowlists cannot be written
- [x] Allowed commands can still execute arbitrary project code
- [ ] They are the same thing

*Answer:* Allowed commands can still execute arbitrary project code. An allowlist limits requests; a sandbox limits what any process can actually reach.
