Skip to content

Per-project permission manifest (.vibe-sec.json) #6

@kobzevvv

Description

@kobzevvv

Developers want per-project security policies. A scraper legitimately uses curl. A wallet app should never touch network. Most-requested missing feature in AI agent security. Proposal: .vibe-sec.json in project root with allow/deny patterns, protected_paths, committable to version control. Hook reads it when present, project rules take precedence over global allowlist.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions