Skip to content

disable permissions via config #697

Description

@yookibooki

add option to disable permissions in config

Activity

  1. lfaoro commented on Jul 15, 2026

    @lfaoro
    Contributor

    please provide more context

  2. yookibooki commented on Jul 15, 2026

    @yookibooki
    Author

    What "permissions" means in Zero

    Zero has a permission mode system that controls whether the agent prompts the user before taking side-effectful actions (writing files, running shell commands, network access, etc.). The modes are:

    • ask — interactive default; prompts before every write/shell/network action
    • auto — auto-approves low-risk tools, prompts for higher-risk ones
    • unsafe — disables permission prompts entirely; all tool calls are auto-allowed (the sandbox still enforces hard blocks like out-of-workspace writes)

    The current situation

    Right now, the only way to run in unsafe mode is to pass --skip-permissions-unsafe as a CLI flag on every invocation, or use --auto high with zero exec. There is no way to persist this preference in the config file.

    The FileConfig struct (internal/config/types.go) supports fields like sandbox, notify, tools, mcp, etc., but has no permissionMode field.

    What this feature request is asking for

    Add a permissionMode (or similar) key to the config file (e.g. ~/.config/zero/config.json or the project-level config) so users can set their preferred mode persistently. For example:

    {
      "permissionMode": "unsafe"
    }

    Use case

    This is useful for trusted local environments or CI pipelines where the user doesn't want to pass --skip-permissions-unsafe on every run, and doesn't want to be interrupted by permission prompts. It's essentially a "remember my choice" for the permission mode.

  3. Vasanthdev2004 commented on Aug 12, 2026

    @Vasanthdev2004
    Collaborator

    @yookibooki what are you trying to get to here? Asking because there are already a few ways to turn the friction down, and which one fits depends on what is actually in your way:

    If none of those cover it, say which prompt is getting in your way and I will look at that specifically.

    Holding off on approving a blanket "disable permissions" switch, because the permission gate is the thing Zero is actually for. A single config key that turns it all off is the one setting most likely to be copied from a blog post into a machine where it should not be, and it would apply to project config unless carefully scoped. Happy to be shown a case that needs it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions