Skip to content

Permissions

Tarsk includes permission gates that keep the agent from running dangerous or unexpected operations without your approval.

When the agent calls the bash tool, Tarsk may pause and show an approval prompt before executing the command. Review the full command, then choose Allow, allow matching commands through an option such as “Always allow <pattern>”, or choose Skip. Tarsk caches an allowed command for that project during the server session. Skipped commands return an error to the agent so it can try a different approach.

Shell commands run in the workspace’s working directory with the project’s environment variables applied.

When the agent calls the fetch tool to retrieve a URL, Tarsk may show a permission prompt listing the URL and domain. Pre-approved domains may skip the prompt.

You can allow or deny each fetch individually. Denied fetches return an error to the agent so it can try an alternative approach.

Confirm Commands lives under Settings → Settings (General Settings):

SettingBehaviour
Off (default)Bash, skill scripts, and browser shell calls run without per-command approval
OnCommands require approval unless an allowed pattern or cached approval permits them

When confirm commands is enabled, define allowed command patterns on the same page — commands matching these patterns (e.g. npm test, git status) run automatically without prompting. The setting applies app-wide, not per project.

When Sandbox is enabled in app-wide settings or the mode selector menu, bash and skill script execution runs inside a macOS seatbelt sandbox. See General Settings.

Scripts in skill scripts/ directories run through the same approval gate as bash commands when confirm commands is enabled.