Skip to main content

Toolkit

Settings & Policy · Pitfalls

On this page7 sections

Pitfalls

Reading One File as Effective Configuration

Overrides and managed sources may change the result. Inspect resolved state.

Tool Denies as Complete Containment

Equivalent actions may remain available through shell, MCPUSB-C for AI — one standard plug so any agent can connect to any data source or tool.The Model Context Protocol: an open standard (Anthropic, 2024) for connecting AI systems to external tools and data without building a custom integration for each one.Full definition, nested agents, IDEs, or cloud execution.

Broad Convenience Permissions

Persistent “allow all” choices turn temporary workflow friction into durable authority. Scope rules narrowly and review them.

Repository-Controlled Policy

An untrusted repository should not be able to grant itself credentials or weaken organization controls.

Local-Cloud Assumption

Hosted identities, networks, filesystems, and approvals differ. Qualify each surface.

Policy Without Negative Tests

A configuration screenshot proves intent, not containment. Attempt the prohibited actions.

Falsification Checklist

  • Which configuration sources won precedence?
  • Can another tool path reach the same protected outcome?
  • Can repository content weaken the rule?
  • Do nested agents inherit more access than intended?
  • Is release still blocked when the local AgentA worker you delegate to: brief it, and it takes steps on its own. A chatbot answers; an agent acts.An LLM that runs tools in a loop toward a goal — it acts, checks the result, decides the next step, and repeats until done.Full definition configuration is bypassed?

Source register

Settings & Policy sources

Primary vendor documentation reviewed on the date shown. Links may change after publication.

  1. Claude Code settings (opens in a new tab)

    Anthropic · official docs · accessed 2026-08-01

  2. Codex config basics (opens in a new tab)

    OpenAI · official docs · accessed 2026-08-01

  3. Overview of customizing GitHub Copilot CLI (opens in a new tab)

    GitHub · official docs · accessed 2026-08-01

  4. GitHub Copilot CLI command reference (opens in a new tab)

    GitHub · official docs · accessed 2026-08-01