Danger Zone: Some Actions Are Hardcoded as Never Allowed

Beyond the rules system, the code also contains a hardcoded dangerous-operations list (src/utils/permissions/dangerousPatterns.ts), primarily used during the cleanup that happens when entering Auto Mode.

// Cross-platform dangerous commands (Unix + Windows)
const CROSS_PLATFORM_CODE_EXEC = [
  'python', 'python3', 'node', 'deno', 'tsx',
  'ruby', 'perl', 'php', 'lua',    // Various interpreters
  'npx', 'bunx', 'npm run',        // Package runners
  'bash', 'sh', 'ssh',             // Shell and remote execution
]

// Unix-additional dangerous commands
const DANGEROUS_BASH_PATTERNS = [
  ...CROSS_PLATFORM_CODE_EXEC,
  'zsh', 'fish', 'eval', 'exec',  // More shells
  'env', 'xargs', 'sudo',          // Privilege escalation
]

Why are these dangerous? Because a broad allow rule like Bash(python:*) effectively permits Claude to execute arbitrary code through Python, completely bypassing the fine-grained checks on Bash commands. When entering Auto Mode, the system automatically strips these kinds of rules, preventing the AI classifier from over-trusting decisions made under overly broad authorization.