AI Hardening: Least-Privilege Agent Tools
The DevOps Assistant currently has unrestricted file access. Scope it down.
The agent's real job needs access to these (should be ALLOWED by your pattern)
- /var/log/app/access.log
- /var/log/app/error.log
- /var/log/app/debug.log
- /etc/app/config.yaml
The agent must never be able to reach these (should be DENIED by your pattern)
- /etc/shadow
- /home/admin/.ssh/id_rsa
- /etc/app/.env
- /root/.aws/credentials
- /var/log/app/../../../etc/shadow
Submit your allowlist pattern
Submit a regular expression. A requested path is ALLOWED only if your pattern MATCHES it; everything else is denied. Max 300 characters.