5bd07af1fe287a5cc9ad103d88d19ba98a9c44bd

Author
TheEdgeOfRage <git@theedgeofrage.com>
Committer
TheEdgeOfRage <git@theedgeofrage.com>
Date

Message

default tools to allow

Diff

 1diff --git a/README.md b/README.md
 2index d6625ec14b0c259d85a48e25b92f533c01126927..81d7a0f6cc6fc7cdc473803c2ce25524d9e36014 100644
 3--- a/README.md
 4+++ b/README.md
 5@@ -75,14 +75,13 @@ LLM review sends the complete tool input to the configured provider. Do not use
 6 
 7 ## Pi permissions
 8 
 9-Pi uses a root-level `tools` map and `externalDirectories` list. Any tool name can be configured. An omitted tool defaults to `check`.
10+Pi uses a root-level `tools` map and `externalDirectories` list. Any tool name can be configured. An omitted tool defaults to `allow`; set a tool to `check` for LLM review.
11 
12 ```json
13 {
14   "tools": {
15     "bash": "check",
16-    "read": "allow",
17-    "my_extension_tool": "allow"
18+    "my_extension_tool": "check"
19   },
20   "externalDirectories": ["/tmp/pi"]
21 }
22diff --git a/src/pi/static-permissions.ts b/src/pi/static-permissions.ts
23index 99129d4b6a2503af433d15a091674e99e25bd44b..d7eb8903c323cc7b1aeedf134e84115f3f6ac69d 100644
24--- a/src/pi/static-permissions.ts
25+++ b/src/pi/static-permissions.ts
26@@ -70,7 +70,7 @@ export async function checkStaticPermission(
27   cwd: string,
28   config: PiPolicyEngineConfig,
29 ): Promise<Decision | undefined> {
30-  const action = config.tools[toolType] ?? "check";
31+  const action = config.tools[toolType] ?? "allow";
32   if (action === "deny") return staticDecision(action, `Static ${toolType} permission`, "config_allow");
33 
34   let externalPath: string | undefined;
35diff --git a/test/pi/static-permissions.test.ts b/test/pi/static-permissions.test.ts
36index 64782cc574959938c3c50dc7295740f235c98d49..a9d4c961f98876a088dd0c448f3167c3107066be 100644
37--- a/test/pi/static-permissions.test.ts
38+++ b/test/pi/static-permissions.test.ts
39@@ -20,6 +20,19 @@ test("explicit deny wins before external path handling", async () => {
40   }
41 });
42 
43+test("allows unconfigured tools and checks configured tools", async () => {
44+  const config: PiPolicyEngineConfig = { reviewer: { kind: "none" }, tools: {}, externalDirectories: [] };
45+  await expect(checkStaticPermission("my_extension_tool", {}, process.cwd(), config)).resolves.toMatchObject({
46+    decision: "allow",
47+  });
48+  await expect(
49+    checkStaticPermission("my_extension_tool", {}, process.cwd(), {
50+      ...config,
51+      tools: { my_extension_tool: "check" },
52+    }),
53+  ).resolves.toBeUndefined();
54+});
55+
56 test("asks before changing a policy engine configuration", async () => {
57   const cwd = mkdtempSync(join(tmpdir(), "policy-engine-cwd-"));
58   try {