security: the project check command runs model-edited code without a command approval when the sandbox is off
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 67/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- node.js, typescript
Research direction
Start with src/main/chat_manager.ts at lines 451–453 and 509–513, then read src/main/agent/edit_check.ts at lines 49–55 to trace how automatic checks reach shell.run. Review how sandbox mode is determined and how the existing approval flow handles run_command. Done when checks that may run edited project code are skipped or require approval with the sandbox off, and the behavior is documented.
Written by the indexing model from the issue text.
Description
Found in the Oct 11 audit (at c5f5641). Related to #272.
Where: src/main/chat_manager.ts:451-453 and :509-513; src/main/agent/edit_check.ts:49-55.
Cause: after any batch of edits, checkCommand runs through shell.run with no approval card, because the user confirmed the command itself in settings. Typical check commands (npm test, npm run lint, eslint) run project code the model can write: tests, eslint.config.mjs, package.json scripts.
Impact: in Ask mode run_command needs approval, but one approved edit of a test or config file, or an edit auto-allowed by a rule such as edit_file src/*, runs model-written code right away. That is unsandboxed when sandbox mode is off.
Fix: skip the automatic check (or ask) when the sandbox is off, and document that the check runs code from edited files.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 28m
- Merged PRs (30d)
- 24
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
Claude Code chats: tool calls made inside Claude Code subagents leave cards that end as "(stopped)"Openbug priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 83/100
PierrunoYT/patch#289 ·
Maintainers usually reply within 1 day
-
bug priority: medium severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#285 ·
Maintainers usually reply within 1 day
-
priority: medium security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
PierrunoYT/patch#283 ·
Maintainers usually reply within 1 day
-
enhancement priority: medium security severity: medium
Difficulty 5/5 Over a week Newbie friendliness 35/100
PierrunoYT/patch#294 ·
Maintainers usually reply within 1 day
-
priority: low security severity: low
Difficulty 4/5 1-2 days Newbie friendliness 38/100
PierrunoYT/patch#293 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 77/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
cline/mcp-marketplace#2932 ·
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficulty 1/5 Under an hour Newbie friendliness 82/100
lingdojo/kana-dojo#32188 · 1 comment · 5 reactions ·
Maintainers usually reply within 1 day
-
triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Portkey-AI/gateway#1844 ·
Maintainers usually reply within 1 day
-
needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 61/100
rjsf-team/react-jsonschema-form#5495 ·
Maintainers usually reply within 2 days