Auto-allow config has ‘File-Deletion Protection’ and ‘External-File Protection’ but no protection against killing processes.
I tested auto-allow to spawn a Streamlit server, and the agent killed a Streamlit server running under root (I had created it with nohup setsid) because the agent wanted to use the same port (for no good reason).
I cannot use Auto-allow until this security gap is filled. So I’m signal-boosting this by creating this post.
Furthermore: Perhaps Auto-allow could involve a custom user instructions MD to finely control what is (not) auto-allowed.
Cheers,
Dan