sassy_permission
Inspect and modify safety controls for shell and file tools: view the active permission mode, switch between strict, confirm, sandbox, or bypass, and manage sandbox roots or deny rules.
Instructions
Read-only by default, mutating on change actions. Front door to the four-mode safety system gating shell and file tools. action="status" (default) reports the effective mode, derivation, sandbox roots, and active rules. set_mode sets permission.mode to strict (block destructive patterns), confirm (return a confirm token), sandbox (relaxed inside sandbox roots, anything outside is refused), or bypass (allow all except protected paths); mode="" clears the override so it derives from the legacy interceptor.destructiveAction setting. Switching to bypass requires confirm='YES' (exact, case-sensitive); the privilege mutations add_root (widens the sandbox jail), add_rule, and clear_rules also require confirm='YES', while remove_root (shrinks the jail) needs no confirmation. add_rule appends a JSON rule like {"action":"deny","tool":"sassy_shell","command":"rm"} (first match wins, before the mode default); clear_rules empties the list. Invalid modes and rules are rejected. Use to inspect or change safety gating; pair with sassy_shell_confirm in confirm mode.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mode | No | ||
| path | No | ||
| rule | No | ||
| action | No | status | |
| confirm | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |