Skip to content

security: gate assistant-triggered commands by default#59

Open
yetone wants to merge 1 commit intoPsiACE:mainfrom
yetone:alma-suggestions
Open

security: gate assistant-triggered commands by default#59
yetone wants to merge 1 commit intoPsiACE:mainfrom
yetone:alma-suggestions

Conversation

@yetone
Copy link

@yetone yetone commented Feb 17, 2026

This makes assistant-emitted comma-prefixed commands (shell/internal) opt-in via BUB_ALLOW_ASSISTANT_COMMANDS=true. Human comma-prefixed commands remain unchanged. Motivation: reduce risk of accidental/prompt-injected remote command execution, especially when running via Telegram/Discord channels.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant