{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/opencode/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Claude Code","Codex CLI","Gemini CLI","GitHub Copilot CLI","OpenCode"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Anthropic","OpenAI","Google","Microsoft"],"content_html":"\u003cp\u003eGenAI coding agents are designed to assist developers by performing tasks such as file editing, command execution, and code generation. These tools incorporate security guardrails, typically requiring human approval before executing sensitive operations. However, various CLI tools support administrative or sandbox-intended flags that bypass these confirmation prompts, enabling autonomous operation.\u003c/p\u003e\n\u003cp\u003eDefenders have observed these flags - such as \u003ccode\u003e--yolo\u003c/code\u003e, \u003ccode\u003e--dangerously-skip-permissions\u003c/code\u003e, or \u003ccode\u003e--full-auto\u003c/code\u003e - being misused on internet-connected developer workstations. This configuration eliminates human oversight, allowing compromised dependencies, malicious project configurations, or external prompt injection attacks to execute arbitrary shell commands, modify local files, and access sensitive environment credentials without user interaction. This behavior materially increases the blast radius for development environments, as the agent functions with the full privileges of the host user account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this configuration allows attackers to pivot from an initial prompt injection or dependency compromise into full code execution on the developer's workstation. This results in the potential exfiltration of source code, cloud credentials, and local environment variables, potentially leading to downstream supply chain attacks if the developer has access to production CI/CD pipelines.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying the execution of GenAI agent binaries with permissive command-line arguments.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rules to identify and alert on GenAI agents started with bypass flags in non-sandbox environments.\u003c/li\u003e\n\u003cli\u003eAudit and restrict the usage of GenAI agent permission-bypass flags via organization-wide security policies.\u003c/li\u003e\n\u003cli\u003eAudit active GenAI configurations, including MCP server settings and skill definitions, for unauthorized modifications.\u003c/li\u003e\n\u003cli\u003eEnsure developers follow a \u0026quot;plan-only\u0026quot; or \u0026quot;default\u0026quot; permission mode for all interactive work on networked endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:09:57Z","date_published":"2026-09-18T19:09:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-genai-cli-bypass/","summary":"The misuse of permission-bypass or auto-approval flags in GenAI CLI agents disables critical human-in-the-loop guardrails, creating significant risks for prompt injection and unauthorized autonomous system modification on developer workstations.","title":"Unsafe Permission Bypass in GenAI CLI Agents","url":"https://feed.craftedsignal.io/briefs/2026-09-genai-cli-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenCode","version":"https://jsonfeed.org/version/1.1"}