Coding agent permissions, without --dangerously-skip-permissions
Coding agent permissions are the rules that decide which tool calls an agent such as Claude Code, Codex, Cursor, Gemini CLI or Windsurf may run on its own, which it must ask you about, and which it may never run. Every agent ships its own system for this, in its own format. Most people meet it as a prompt that appears too often, and switch it off.
This page covers each agent's permission settings, what the flags that skip them really skip, and how to stop being asked about the safe calls without giving up the dangerous ones. The last part is what Memnox is for, and it needs no account.
Every agent's permission settings at a glance
| Agent | Where the rules live | Mode that asks less | Mode that asks nothing |
|---|---|---|---|
| Claude Code | permissions.allow, ask and deny in settings.json | acceptEdits, auto | bypassPermissions, or --dangerously-skip-permissions |
| Codex | approval_policy and sandbox_mode in config.toml | on-request with workspace-write | --dangerously-bypass-approvals-and-sandbox, alias --yolo |
| Cursor | the run mode, and permissions.json for Auto-review | Auto-review, Allowlist | Run Everything |
| Gemini CLI | tools.allowed and tools.exclude in settings.json | --approval-mode auto_edit | --yolo, or --approval-mode yolo |
| Windsurf | the Cascade allow list and deny list | Allowlist Only, Auto | Turbo |
Each row is taken from that agent's own documentation, which is linked in its section below. The names change between releases, so check them there before you rely on one.
Claude Code permissions
Claude Code has six permission modes:
| Mode | What it does |
|---|---|
default | asks the first time each tool is used |
acceptEdits | accepts file edits and common filesystem commands in the working directory without asking |
plan | reads and explores, and edits nothing |
auto | approves tool calls after a background safety check that they match your request |
dontAsk | denies anything that would have asked, and runs what is already allowed |
bypassPermissions | skips permission prompts, apart from the few actions no mode approves on its own |
You pick one with --permission-mode, and --dangerously-skip-permissions is
the same as starting in bypassPermissions. Rules go in settings.json:
{
"permissions": {
"allow": ["Bash(npm run *)"],
"ask": ["WebFetch(domain:example.com)"],
"deny": ["Read(./.env)"]
}
}Claude Code checks deny first, then ask, then allow, and the first match wins. A
broad deny such as Bash(aws *) beats a narrower allow such as
Bash(aws s3 ls), so an allow rule cannot make an exception to a deny.
What --dangerously-skip-permissions actually skips
It skips the prompt, which is the only place Claude Code asks you anything. What
the agent can reach does not change: your SSH keys, your cloud credentials, every
repository you can push to and every MCP server you have connected. Nothing is
checked before a call runs, apart from the handful of actions Claude Code never
approves on its own. People turn it on because default asks about ls, and
the price is that it no longer asks about git push --force either.
Claude Code auto mode
auto is the mode most people pick when default asks too often. It approves a
tool call after a background check that the call matches what you asked for,
and a call that fails the check is denied. That check is a judgement made by a
model, so the same call can be judged differently on another day, and it asks
whether a call matches your request, which is a different question from whether
it is a call you would ever want run. A rule matched against the action gives the same
answer every time, which is what the steps below
add. If you mostly want to limit how far a command can reach, the
Claude Code sandbox is the other half.
Codex permissions: approval policy and sandbox
Codex splits
permissions into two settings. The sandbox mode is what Codex can do at all:
read-only, workspace-write or danger-full-access. The approval policy
is when it has to ask: on-request asks before it leaves the sandbox, and
never never asks.
approval_policy = "on-request"
sandbox_mode = "workspace-write"--dangerously-bypass-approvals-and-sandbox, with its alias --yolo, removes
both at once, so there is no sandbox and nothing is ever asked.
Cursor auto-run modes
Cursor decides how its agent runs shell commands, MCP calls and fetches with a run mode:
| Run mode | What it does |
|---|---|
| Auto-review | runs your allowlist at once, sandboxes what it can, and sends the rest to a classifier |
| Allowlist | runs only what is on your allowlist without asking |
| Run Everything | runs every tool call without asking, which is what people still call YOLO mode |
Auto-review reads allow_instructions and block_instructions from
permissions.json, which are descriptions the classifier leans on rather than
rules it has to follow.
Gemini CLI approval modes and --yolo
Gemini CLI has four
approval modes, default, auto_edit, plan and yolo, set with
--approval-mode. auto_edit approves edits and asks about everything else, and
--yolo approves every tool call. tools.allowed and tools.exclude in
settings.json name the tools that run without asking and the tools the agent
never sees, and security.disableYoloMode is the setting that switches --yolo
off.
Windsurf auto-execution levels
Windsurf's Cascade has four levels for terminal commands: Disabled, Allowlist Only, Auto, where the model judges what is safe, and Turbo, which runs everything that is not on your deny list. A deny list entry always asks before it runs, whatever the level.
Why the built-in settings stop short
They are good at what they do. Four things are out of their reach.
- Each one knows only its own agent. Five agents on one laptop means five rule files in five formats. A deny you wrote for Claude Code does nothing when the same task runs in Cursor.
- A rule names a tool, not what it is done to.
Bash(git *)cannot tell a push to a branch from a force push tomainwithout a pattern for every case, and some agents only let you describe what to lean towards. - The mode that stops the asking stops the checking. Skip permissions,
--yolo, Run Everything and Turbo are all one switch that removes the questions and the refusals together. There is no setting for "stop asking about the safe ones". - Nothing learns what you already approved. You answer yes to
npm testa hundred times and are asked the hundred and first.
How to stop being asked, safely
Put a rule between the agent and the call, one that answers every call with allow, ask or deny before it runs, whichever agent made it. That is what Memnox does. It is open source, it runs on your machine, and no model decides anything, so a prompt cannot talk a rule round. It is built on each agent's own hooks, and on an MCP proxy for every MCP server.
Set it up once
bashnpm install -g memnox memnox setupsetupfinds the agents on this machine, shows you what each can reach, and puts a hook in front of every tool call of each one you accept. Start inobserve, which records what every rule would have said and stops nothing.Write the rules once, for every agent
One rule file covers Claude Code, Codex, Cursor, Gemini CLI and Windsurf, and a deny names what the agent should do instead, so it finishes the task rather than stalling:
tomlversion = 1 [[policies]] name = "no-force-push-to-main" [policies.match] actions = ["git.push*"] targets = ["*main*"] [policies.decision] effect = "deny" reason = "main is shared, and a force push loses somebody's work." [policies.decision.alternative] action = "git.push" resource = "a branch" note = "Push a branch and open a PR."memnox protectproposes a starting set from what your agents can actually reach, andmemnox protect --apply-nativealso writes the rules into Claude Code's own permissions, so they hold even where Memnox is not in the path.Answer less as you go
In Claude Code a question arrives in its own permission prompt, and you can say yes once or yes for the session. When you want a quiet hour, allow a scope for a while:
bashmemnox allow "railway.*" --env staging --for 30m --reason "reproducing the retry bug"Hand over what you always approve
bashmemnox nextnextreads what you have already approved and names what you have said yes to often enough that being asked again wastes your attention. One refusal removes a recommendation, and a destructive or outward action is never handed over however routine it became.memnox next --hand-overwrites the allow rules for everything that is ready.
The result is the mode the agents do not have: routine calls run without a prompt, the dangerous ones are still denied, and the few that need you still ask.
What each agent gets from Memnox
| Agent | Checked before it runs | Where a question goes |
|---|---|---|
| Claude Code | every tool | its own permission prompt |
| Codex | every tool its hook reports | the conversation |
| Gemini CLI | every tool | the conversation |
| Cursor | commands, MCP calls, file reads and writes | its own prompt for commands and MCP calls |
| Windsurf | commands, MCP calls, file reads and writes | memnox approve, your workspace or your DM |
What still holds in bypass mode
If you keep running Claude Code with --dangerously-skip-permissions, a Memnox
deny still stops the call, because the hook runs before the call whatever the
mode. There is no prompt to ask in, so a question is relayed in the session, and
on an unattended run a question nobody answers is refused when it times out,
unless somebody answers it from memnox approve, the workspace or a DM. A write
outside the repository the session started in is refused in this mode rather
than asked. Memnox in your session has the details.
Questions people ask
Is --dangerously-skip-permissions safe?
It is as safe as everything the agent can reach. The flag removes every prompt,
so a force push, a deleted directory or a read of ~/.ssh runs without a
question. It is reasonable inside a throwaway container. On your own laptop, keep
a rule layer such as Memnox in front of it.
How do I make Claude Code stop asking for permission?
Add the commands you trust to permissions.allow in settings.json, or use
acceptEdits for edits. To stop being asked across every agent without losing
the refusals, run memnox setup, then memnox next to see what you already
approve often enough to hand over.
What is Claude Code auto mode?
A permission mode that approves tool calls after a background check that they match what you asked for. The check is a judgement made by a model. Memnox rules are matched, not judged, so the same call gets the same verdict every time.
What is Cursor YOLO mode?
The name people still use for Run Everything, the Cursor run mode where every tool call runs without asking. Allowlist and Auto-review are the modes that keep some calls behind a question.
How do I turn off approvals in Codex?
Set approval_policy = "never" in config.toml, or start Codex with
--dangerously-bypass-approvals-and-sandbox, alias --yolo, which also drops
the sandbox. Keeping workspace-write with on-request stops most prompts and
keeps the sandbox.
Can one set of rules cover every coding agent?
Yes. Memnox reads one rule file and holds it in Claude Code, Codex, Cursor, Gemini CLI and Windsurf, each through that agent's own hook, and answers every call with allow, ask or deny.

