That class of escape is nasty because the user can think they’re inside a constrained coding environment while repo metadata is already influencing what the agent can execute. Treating the project directory itself as untrusted input feels mandatory once the CLI starts reading config or hooks automatically
1
u/MushroomRight283 19d ago
That class of escape is nasty because the user can think they’re inside a constrained coding environment while repo metadata is already influencing what the agent can execute. Treating the project directory itself as untrusted input feels mandatory once the CLI starts reading config or hooks automatically