Danger Zone: Some Actions Are Hardcoded as Never Allowed
Beyond the rules system, the code also contains a hardcoded dangerous-operations list (src/utils/permissions/dangerousPatterns.ts), primarily used during the cleanup that happens when entering Auto Mode.
// Cross-platform dangerous commands (Unix + Windows)
const CROSS_PLATFORM_CODE_EXEC = [
'python', 'python3', 'node', 'deno', 'tsx',
'ruby', 'perl', 'php', 'lua', // Various interpreters
'npx', 'bunx', 'npm run', // Package runners
'bash', 'sh', 'ssh', // Shell and remote execution
]
// Unix-additional dangerous commands
const DANGEROUS_BASH_PATTERNS = [
...CROSS_PLATFORM_CODE_EXEC,
'zsh', 'fish', 'eval', 'exec', // More shells
'env', 'xargs', 'sudo', // Privilege escalation
]
Why are these dangerous? Because a broad allow rule like Bash(python:*) effectively permits Claude to execute arbitrary code through Python, completely bypassing the fine-grained checks on Bash commands. When entering Auto Mode, the system automatically strips these kinds of rules, preventing the AI classifier from over-trusting decisions made under overly broad authorization.