open-coder-ai/block-unguarded-agent-spawn
Best-effort guard against an agent launching a coding agent with its safety checks off: claude --dangerously-skip-permissions or --permission-mode bypassPermissions, codex --full-auto, --yolo, --dangerously-bypass-approvals-and-sandbox or --sandbox danger-full-access, gemini --yolo, -y or --approval-mode yolo, cursor-agent --force. A spawned agent that never asks and never sandboxes is an unsupervised agent (OWASP ASI10, rogue agents). Read as a parsed command, so cd repo && claude ..., bash -c '...', sudo/env wrappers and npx @openai/codex ... are caught, while a normal invocation, codex --sandbox workspace-write, or a command that only mentions the flag (echo, grep, a commit message) is not. Known bypass classes include shell aliases, wrapper scripts, config files that set the mode, and agents this list does not name. Run the agent with its default approvals; a human decides when an unattended run is acceptable.
What this package declares
The file a client reads when it loads this plugin, exactly as this revision carries it.
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "block-unguarded-agent-spawn",
"version": "0.0.1",
"description": "Best-effort guard against an agent launching a coding agent with its safety checks off: claude --dangerously-skip-permissions or --permission-mode bypassPermissions, codex --full-auto, --yolo, --dangerously-bypass-approvals-and-sandbox or --sandbox danger-full-access, gemini --yolo, -y or --approval-mode yolo, cursor-agent --force. A spawned agent that never asks and never sandboxes is an unsupervised agent (OWASP ASI10, rogue agents). Read as a parsed command, so `cd repo && claude ...`, `bash -c '...'`, sudo/env wrappers and `npx @openai/codex ...` are caught, while a normal invocation, `codex --sandbox workspace-write`, or a command that only mentions the flag (echo, grep, a commit message) is not. Known bypass classes include shell aliases, wrapper scripts, config files that set the mode, and agents this list does not name. Run the agent with its default approvals; a human decides when an unattended run is acceptable.",
"author": {
"name": "chock-core"
},
"repository": "https://github.com/open-coder-ai/chock-catalog",
"license": "Apache-2.0",
"keywords": [
"chock",
"policy-as-code",
"rule",
"advise",
"{'control': 'asi10', 'coverage': 'partial', 'note': 'refuses launching a sub-agent with approvals or sandbox switched off from the shell; agent inventory, expiry, monitoring and a kill switch stay with the advisory owasp-asi10-rogue-agents policy'}"
],
"extensions": {
"io.github.open-coder-ai": {
"manifest": "manifest.yaml",
"artifact": "rule",
"enforcement": "advise",
"coverage_without_chock": "advisory"
}
}
}
What else this package ships
These files come with the package and this site does not publish them. They are listed so you know what is there before you install it.
- LICENSE
Client extensions
Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.
- io.github.open-coder-ai