Repository navigation
Conversation
nimat-dev
commented
Oct 8, 2026
nimat-dev
left a comment
Owner
Author
There was a problem hiding this comment.
Maker-Checker Evaluation: F008 (Permission bridge + confirm UI + allowlist + audit log)
-
Acceptance Criteria Verification:
- Intercepts stdio permission prompts from Claude Code and surfaces
perm.requestacross Tailnet transport: PASS. - Pure
classifyRiskdetects read-only (low), writes (medium), and destructive commands (high): PASS. - Pure
isReadonlyCommandallowlist auto-approves safe read-only operations without human friction: PASS. - Append-only file audit log with mode 0600 written BEFORE executing approved operations: PASS.
- Edge cases tested: timeout to default deny, double-tap idempotency, disconnect abort & pending rejection, device revocation immediate denial, chained/obfuscated command detection: PASS.
- Mobile
PermissionCardcomponent with color-coded risk badge, session checkbox, Allow/Deny actions: PASS.
- Intercepts stdio permission prompts from Claude Code and surfaces
-
Architecture & Boundaries:
- Zero Node builtins or I/O in
packages/protocolandpackages/agent/src/core. - Dependency-cruiser: 61 modules cruised, 0 violations. Clean architecture verified.
- Zero Node builtins or I/O in
-
Test Battery & CI:
- 99/99 tests passing monorepo-wide.
- GitHub Actions CI checks all green.
Ready for squash merge.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements F008 — Permission bridge + confirm UI + allowlist + audit log:
packages/protocol):RiskHintenum:"low" | "medium" | "high".classifyRisk(toolName, input): detects safe read-only operations ("low"), file writes/modifications ("medium"), and destructive patterns ("high" —rm,sudo,dd,git reset --hard, chained&& rm,$()).isReadonlyCommand(toolName, input): allowlist evaluator.perm.requestandperm.responseenvelopes, Zod schemas, and serializers.packages/agent/src/core):IPermissionBridge,PermissionRequest,PermissionDecisioninsrc/core/permission.ts(0 Node builtins or I/O imports).IAuditLogger,AuditEntryinsrc/core/audit.ts(0 Node builtins or I/O imports).packages/agent/src/adapters):PermissionBridge: auto-allows safe read-only operations without interrupting the user, prompts mobile client for writes/destructive actions, session allowlist with "remember for session", 60s timeout to default deny, idempotent double-tap resolution,denyAllPending()on disconnect/abort/revocation.FileAuditLogger: atomic append-only JSONL file logger with mode0600; written before releasing execution of dangerous commands; rejects tool if audit writing fails.ClaudeStreamParser&LocalClaudeDriver: intercepts stdiocontrol_request(can_use_tool) from Claude Code, queriesPermissionBridge, and sendscontrol_response(allowordeny) back over stdin.AgentDaemon: routesperm.requestto connected mobile client, handlesperm.response, denys pending on disconnect or device revocation.packages/mobile):onPermissionRequest()andrespondPermission()inAgentClient.PermissionCard.tsx: React Native component displaying tool name, command box, cwd, color-coded risk badge (Green/Amber/Red), remember checkbox, and Allow/Deny buttons..maestro/permission_flow.yaml..harness/evidence/F008/(arch-summary.txt,test-summary.txt,e2e-trace.txt).