mirror of
https://github.com/MadsLorentzen/ai-job-search.git
synced 2026-09-17 16:46:24 +00:00
The upstream template pre-approves `Bash(bun run:*)`, which auto-approves `bun run <any file>` — arbitrary TypeScript from anywhere on disk — on every fork. Each portal SKILL.md already declares the tight form in its own allowed-tools; this makes settings.json agree with them. Blast radius drops from "any file on the machine" to the repo's own CLIs, with no new prompts in the /scrape path. tools/security_guards.py's ALLOWED_PERMISSIONS is updated in the same commit, as its docstring requires. Local: security_guards OK, lint_skills OK, 318 tests pass. Claude-Session: https://claude.ai/code/session_01HHqEAQqGS2KKXASiYcrAHQ
19 lines
713 B
JSON
19 lines
713 B
JSON
{
|
|
"permissions": {
|
|
"allow": [
|
|
"Skill(job-application-assistant)",
|
|
"Bash(bun run .agents/skills/jobbank-search/cli/src/cli.ts:*)",
|
|
"Bash(bun run .agents/skills/jobdanmark-search/cli/src/cli.ts:*)",
|
|
"Bash(bun run .agents/skills/jobindex-search/cli/src/cli.ts:*)",
|
|
"Bash(bun run .agents/skills/jobnet-search/cli/src/cli.ts:*)",
|
|
"Bash(bun run .agents/skills/linkedin-search/cli/src/cli.ts:*)",
|
|
"Bash(bun run .agents/skills/freehire-search/cli/src/cli.ts:*)",
|
|
"Bash(python salary_lookup.py:*)",
|
|
"Bash(python3 salary_lookup.py:*)",
|
|
"Bash(python tools/verify_pdf.py:*)",
|
|
"Bash(python3 tools/verify_pdf.py:*)",
|
|
"Bash(pdftotext:*)"
|
|
]
|
|
}
|
|
}
|