# Allowed Commands भी कोड चला सकते हैं — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/hi/coding-agent-guardrails/perm-allowed-can-run-code

> समझें कि test runners जैसे "सुरक्षित" commands भी project का कोड चलाते हैं, और उसकी योजना बनाएँ।

## npm test कोड का निष्पादन है

`npm test` को allow करना सुरक्षित लगता है, पर वह `test` script और test files में जो भी है वह चलाता है, और agent दोनों बदल सकता है। यही `make`, `pytest`, build tools और install scripts पर लागू है। इसलिए allowlist **sandbox नहीं है**: वह माँगे जा सकने वाले को घटाता है, पर मंज़ूर commands वह सब कर सकते हैं जो project कोड करता है। इसीलिए command नीति को sandbox, environment में कोई secret नहीं और network allowlist के साथ मिलाना चाहिए।

## जोखिम कहाँ छिपता है

Test script में कोई भी shell command हो सकता है। Agent `package.json` बदल सकता है और `npm test` चला सकता है, तो उसके पास अप्रत्यक्ष shell access है।

```json
{
  "scripts": {
    "test": "jest && node scripts/anything.js"
  }
}
```

## Commands परिभाषित करने वाली files की रक्षा करें

`package.json`, `Makefile`, CI files और lockfiles को protected paths मानें जिन्हें बदलने के लिए मंज़ूरी चाहिए, क्योंकि उन्हें बदलने से "सुरक्षित" commands का काम बदल जाता है।

**Quiz:** Allowlist sandbox क्यों नहीं है?

- [ ] Sandboxes धीमे हैं
- [ ] Allowlists लिखे नहीं जा सकते
- [x] Allowed commands फिर भी मनमाना project कोड चला सकते हैं
- [ ] दोनों एक ही चीज़ हैं

*Answer:* Allowed commands फिर भी मनमाना project कोड चला सकते हैं. Allowlist अनुरोध सीमित करता है; sandbox सीमित करता है कि कोई भी process असल में कहाँ पहुँच सकता है।
