39 lines
1.7 KiB
JSON
39 lines
1.7 KiB
JSON
{
|
|
"_schema": "muse-choices-rules/v1",
|
|
"_notes": [
|
|
"Deny/hold dictionary for the muse-choices daemon (decisions D0-D4).",
|
|
"First matching rule wins. Fields: id (required), kind (str|list, optional),",
|
|
"token (str|list, exact match on explicit-phrase key, optional), command",
|
|
"(regex on the approval $ block, approval kinds only, optional), text",
|
|
"(regex on cue+options, optional), decision (approve|deny|hold), reason.",
|
|
"Deny rules apply to permission kinds only (muse-approval, yn) and are",
|
|
"skipped for question kinds (D2). No match => approve top-choice (D4).",
|
|
"Seed policy: risky => hold (operator window, then approve). No active",
|
|
"deny rules yet -- add them from experience, one at a time, with tests."
|
|
],
|
|
"version": 1,
|
|
"rules": [
|
|
{
|
|
"id": "explicit-destructive-token",
|
|
"kind": "explicit-phrase",
|
|
"token": ["ABORT", "DELETE", "DESTROY", "WIPE", "KILL"],
|
|
"decision": "hold",
|
|
"reason": "destructive magic word; hold for operator eyes"
|
|
},
|
|
{
|
|
"id": "cmd-destructive-shell",
|
|
"kind": ["muse-approval", "muse-approval-collapsed"],
|
|
"command": "\\brm\\s+-rf?\\b|\\bmkfs\\b|\\bdd\\s+[^\\n]*\\bof=|\\b(shutdown|reboot|halt|poweroff)\\b|git\\s+push\\S*\\s+--force\\b|git\\s+reset\\s+--hard\\b|\\bterraform\\s+(destroy|apply)\\b",
|
|
"decision": "hold",
|
|
"reason": "destructive shell command; hold for operator eyes"
|
|
},
|
|
{
|
|
"id": "cmd-database-drop",
|
|
"kind": ["muse-approval", "muse-approval-collapsed"],
|
|
"command": "(?i)\\bdrop\\s+(table|database|schema)\\b|\\btruncate\\s+table\\b",
|
|
"decision": "hold",
|
|
"reason": "destructive database statement; hold for operator eyes"
|
|
}
|
|
]
|
|
}
|