Skip to content

[capabilities]

Allow and deny rules for filesystem access, command execution, environment variables, and command network access.

Sub-sectionPage
[capabilities.allow]capabilities.allow — Grants the agent can use: reads, writes, commands, network, extra directories.
[capabilities.deny]capabilities.deny — Hard blocks that override every allow.