Skip to content

Coding-agent CLI takes its command allowlist from attacker-writable configuration, or matches it by command name

coding-agent-config-allowlist-trust is a high severity check in the ai category, written in shell. Its source is templates/ai/coding-agent/coding-agent-config-allowlist-trust.sh in cert-x-gen-templates.

Establishes first that the coding-agent CLI refuses to run a marker shell command unattended when no configuration grants it, then grants it through a config-declared allowlist and re-runs. Honouring that allowlist from a 0700 root proves the tool takes execution authority from configuration; honouring the byte-identical allowlist from a 0777 world-writable root proves any local user can grant it. A third arm allowlists only a benign command name and submits that name followed by a marker command, which separates an allowlist matched on the command NAME from one matched on the command actually run. Every arm’s payload is a printf of a random nonce into the probe’s own scratch directory.

Field Value
Id coding-agent-config-allowlist-trust
Severity high
Language shell
Category ai
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 93
CVSS not recorded
Weakness CWE-732
Tags ai, coding-agent, cli, config-trust, allowlist, approval-bypass, privilege-escalation, cwe-732, cwe-863, cwe-183, cve-2026-35603
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info coding-agent-config-allowlist-trust

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.