DocsWhat may it doCoding agent permissions

Coding agent permissions, without --dangerously-skip-permissions

Coding agent permissions are the rules that decide which tool calls an agent such as Claude Code, Codex, Cursor, Gemini CLI or Windsurf may run on its own, which it must ask you about, and which it may never run. Every agent ships its own system for this, in its own format. Most people meet it as a prompt that appears too often, and switch it off.

This page covers each agent's permission settings, what the flags that skip them really skip, and how to stop being asked about the safe calls without giving up the dangerous ones. The last part is what Memnox is for, and it needs no account.

Every agent's permission settings at a glance

AgentWhere the rules liveMode that asks lessMode that asks nothing
Claude Codepermissions.allow, ask and deny in settings.jsonacceptEdits, autobypassPermissions, or --dangerously-skip-permissions
Codexapproval_policy and sandbox_mode in config.tomlon-request with workspace-write--dangerously-bypass-approvals-and-sandbox, alias --yolo
Cursorthe run mode, and permissions.json for Auto-reviewAuto-review, AllowlistRun Everything
Gemini CLItools.allowed and tools.exclude in settings.json--approval-mode auto_edit--yolo, or --approval-mode yolo
Windsurfthe Cascade allow list and deny listAllowlist Only, AutoTurbo

Each row is taken from that agent's own documentation, which is linked in its section below. The names change between releases, so check them there before you rely on one.

Claude Code permissions

Claude Code has six permission modes:

ModeWhat it does
defaultasks the first time each tool is used
acceptEditsaccepts file edits and common filesystem commands in the working directory without asking
planreads and explores, and edits nothing
autoapproves tool calls after a background safety check that they match your request
dontAskdenies anything that would have asked, and runs what is already allowed
bypassPermissionsskips permission prompts, apart from the few actions no mode approves on its own

You pick one with --permission-mode, and --dangerously-skip-permissions is the same as starting in bypassPermissions. Rules go in settings.json:

json
{
  "permissions": {
    "allow": ["Bash(npm run *)"],
    "ask": ["WebFetch(domain:example.com)"],
    "deny": ["Read(./.env)"]
  }
}

Claude Code checks deny first, then ask, then allow, and the first match wins. A broad deny such as Bash(aws *) beats a narrower allow such as Bash(aws s3 ls), so an allow rule cannot make an exception to a deny.

What --dangerously-skip-permissions actually skips

It skips the prompt, which is the only place Claude Code asks you anything. What the agent can reach does not change: your SSH keys, your cloud credentials, every repository you can push to and every MCP server you have connected. Nothing is checked before a call runs, apart from the handful of actions Claude Code never approves on its own. People turn it on because default asks about ls, and the price is that it no longer asks about git push --force either.

Claude Code auto mode

auto is the mode most people pick when default asks too often. It approves a tool call after a background check that the call matches what you asked for, and a call that fails the check is denied. That check is a judgement made by a model, so the same call can be judged differently on another day, and it asks whether a call matches your request, which is a different question from whether it is a call you would ever want run. A rule matched against the action gives the same answer every time, which is what the steps below add. If you mostly want to limit how far a command can reach, the Claude Code sandbox is the other half.

Codex permissions: approval policy and sandbox

Codex splits permissions into two settings. The sandbox mode is what Codex can do at all: read-only, workspace-write or danger-full-access. The approval policy is when it has to ask: on-request asks before it leaves the sandbox, and never never asks.

toml
approval_policy = "on-request"
sandbox_mode    = "workspace-write"

--dangerously-bypass-approvals-and-sandbox, with its alias --yolo, removes both at once, so there is no sandbox and nothing is ever asked.

Cursor auto-run modes

Cursor decides how its agent runs shell commands, MCP calls and fetches with a run mode:

Run modeWhat it does
Auto-reviewruns your allowlist at once, sandboxes what it can, and sends the rest to a classifier
Allowlistruns only what is on your allowlist without asking
Run Everythingruns every tool call without asking, which is what people still call YOLO mode

Auto-review reads allow_instructions and block_instructions from permissions.json, which are descriptions the classifier leans on rather than rules it has to follow.

Gemini CLI approval modes and --yolo

Gemini CLI has four approval modes, default, auto_edit, plan and yolo, set with --approval-mode. auto_edit approves edits and asks about everything else, and --yolo approves every tool call. tools.allowed and tools.exclude in settings.json name the tools that run without asking and the tools the agent never sees, and security.disableYoloMode is the setting that switches --yolo off.

Windsurf auto-execution levels

Windsurf's Cascade has four levels for terminal commands: Disabled, Allowlist Only, Auto, where the model judges what is safe, and Turbo, which runs everything that is not on your deny list. A deny list entry always asks before it runs, whatever the level.

Why the built-in settings stop short

They are good at what they do. Four things are out of their reach.

  • Each one knows only its own agent. Five agents on one laptop means five rule files in five formats. A deny you wrote for Claude Code does nothing when the same task runs in Cursor.
  • A rule names a tool, not what it is done to. Bash(git *) cannot tell a push to a branch from a force push to main without a pattern for every case, and some agents only let you describe what to lean towards.
  • The mode that stops the asking stops the checking. Skip permissions, --yolo, Run Everything and Turbo are all one switch that removes the questions and the refusals together. There is no setting for "stop asking about the safe ones".
  • Nothing learns what you already approved. You answer yes to npm test a hundred times and are asked the hundred and first.

How to stop being asked, safely

Put a rule between the agent and the call, one that answers every call with allow, ask or deny before it runs, whichever agent made it. That is what Memnox does. It is open source, it runs on your machine, and no model decides anything, so a prompt cannot talk a rule round. It is built on each agent's own hooks, and on an MCP proxy for every MCP server.

  1. 1

    Set it up once

    bash
    npm install -g memnox
    memnox setup

    setup finds the agents on this machine, shows you what each can reach, and puts a hook in front of every tool call of each one you accept. Start in observe, which records what every rule would have said and stops nothing.

  2. 2

    Write the rules once, for every agent

    One rule file covers Claude Code, Codex, Cursor, Gemini CLI and Windsurf, and a deny names what the agent should do instead, so it finishes the task rather than stalling:

    toml
    version = 1
     
    [[policies]]
    name = "no-force-push-to-main"
     
    [policies.match]
    actions = ["git.push*"]
    targets = ["*main*"]
     
    [policies.decision]
    effect = "deny"
    reason = "main is shared, and a force push loses somebody's work."
     
    [policies.decision.alternative]
    action = "git.push"
    resource = "a branch"
    note = "Push a branch and open a PR."

    memnox protect proposes a starting set from what your agents can actually reach, and memnox protect --apply-native also writes the rules into Claude Code's own permissions, so they hold even where Memnox is not in the path.

  3. 3

    Answer less as you go

    In Claude Code a question arrives in its own permission prompt, and you can say yes once or yes for the session. When you want a quiet hour, allow a scope for a while:

    bash
    memnox allow "railway.*" --env staging --for 30m --reason "reproducing the retry bug"
  4. 4

    Hand over what you always approve

    bash
    memnox next

    next reads what you have already approved and names what you have said yes to often enough that being asked again wastes your attention. One refusal removes a recommendation, and a destructive or outward action is never handed over however routine it became. memnox next --hand-over writes the allow rules for everything that is ready.

The result is the mode the agents do not have: routine calls run without a prompt, the dangerous ones are still denied, and the few that need you still ask.

What each agent gets from Memnox

AgentChecked before it runsWhere a question goes
Claude Codeevery toolits own permission prompt
Codexevery tool its hook reportsthe conversation
Gemini CLIevery toolthe conversation
Cursorcommands, MCP calls, file reads and writesits own prompt for commands and MCP calls
Windsurfcommands, MCP calls, file reads and writesmemnox approve, your workspace or your DM

What still holds in bypass mode

If you keep running Claude Code with --dangerously-skip-permissions, a Memnox deny still stops the call, because the hook runs before the call whatever the mode. There is no prompt to ask in, so a question is relayed in the session, and on an unattended run a question nobody answers is refused when it times out, unless somebody answers it from memnox approve, the workspace or a DM. A write outside the repository the session started in is refused in this mode rather than asked. Memnox in your session has the details.

Questions people ask

Is --dangerously-skip-permissions safe?

It is as safe as everything the agent can reach. The flag removes every prompt, so a force push, a deleted directory or a read of ~/.ssh runs without a question. It is reasonable inside a throwaway container. On your own laptop, keep a rule layer such as Memnox in front of it.

How do I make Claude Code stop asking for permission?

Add the commands you trust to permissions.allow in settings.json, or use acceptEdits for edits. To stop being asked across every agent without losing the refusals, run memnox setup, then memnox next to see what you already approve often enough to hand over.

What is Claude Code auto mode?

A permission mode that approves tool calls after a background check that they match what you asked for. The check is a judgement made by a model. Memnox rules are matched, not judged, so the same call gets the same verdict every time.

What is Cursor YOLO mode?

The name people still use for Run Everything, the Cursor run mode where every tool call runs without asking. Allowlist and Auto-review are the modes that keep some calls behind a question.

How do I turn off approvals in Codex?

Set approval_policy = "never" in config.toml, or start Codex with --dangerously-bypass-approvals-and-sandbox, alias --yolo, which also drops the sandbox. Keeping workspace-write with on-request stops most prompts and keeps the sandbox.

Can one set of rules cover every coding agent?

Yes. Memnox reads one rule file and holds it in Claude Code, Codex, Cursor, Gemini CLI and Windsurf, each through that agent's own hook, and answers every call with allow, ask or deny.