Live data from Hacker News

Show HN: A police department for your Claude Code agents

github.com

1–10 of 14 posts

Re: Show HN: A police department for your Claude Code agents

#5
Not a criticism, but why would I use this instead of locking down my Claude using the allow/deny permissions list?

    "permissions": {
    "allow": [
      "Bash(npm run lint)",
      "Bash(npm run test *)",
      "Read(~/.zshrc)"
    ],
    "deny": [
      "Bash(curl *)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)"
    ]
  },

Re: Show HN: A police department for your Claude Code agents

#6

Not a criticism, but why would I use this instead of locking down my Claude using the allow/deny permissions list? "permissions": { "allow": [ "Bash(npm run lint)", "Bash(npm run test *)", "Read(~/.zshrc)" ], "deny": [ "Bash(curl *)", "Read(./.env)", "Read(./.env.*)", "Read(./secrets/**)" ] },

Where would one put this? In AGENTS.md?

Re: Show HN: A police department for your Claude Code agents

#7

Not a criticism, but why would I use this instead of locking down my Claude using the allow/deny permissions list? "permissions": { "allow": [ "Bash(npm run lint)", "Bash(npm run test *)", "Read(~/.zshrc)" ], "deny": [ "Bash(curl *)", "Read(./.env)", "Read(./.env.*)", "Read(./secrets/**)" ] },

Where would one put this? In AGENTS.md?

Your settings file: User settings are defined in ~/.claude/settings.json

or /permissions

https://code.claude.com/docs/en/permissions

Re: Show HN: A police department for your Claude Code agents

#8

Not a criticism, but why would I use this instead of locking down my Claude using the allow/deny permissions list? "permissions": { "allow": [ "Bash(npm run lint)", "Bash(npm run test *)", "Read(~/.zshrc)" ], "deny": [ "Bash(curl *)", "Read(./.env)", "Read(./.env.*)", "Read(./secrets/**)" ] },

Idea is not to deny permissions to everything but just keep a log on what the agents are doing thats not in line with our permissions and also you have to know what they are bypassing so we can put them in deny list later. Very useful when you spawn many agents working in parallel. This is more of an observability tool.

Re: Show HN: A police department for your Claude Code agents

#9

Not a criticism, but why would I use this instead of locking down my Claude using the allow/deny permissions list? "permissions": { "allow": [ "Bash(npm run lint)", "Bash(npm run test *)", "Read(~/.zshrc)" ], "deny": [ "Bash(curl *)", "Read(./.env)", "Read(./.env.*)", "Read(./secrets/**)" ] },

Idea is not to deny permissions to everything but just keep a log on what the agents are doing thats not in line with our permissions and also you have to know what they are bypassing so we can put them in deny list later. Very useful when you spawn many agents working in parallel. This is more of an observability tool.

Well at least you'll know why your data was exfiltrated or your systems compromised, even if you can't stop it...
Post reply on HN