{
  "id": 11989534,
  "title": "Your Agent's Allowlist Is a Parser Bug: Build a Shell Command Gate in TypeScript",
  "url": "https://urgent.news/2026/10/04/your-agents-allowlist-is-a-parser-bug-build-a-shell-command-gate-in",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T19:10:18.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bobbyhalljr/your-agents-allowlist-is-a-parser-bug-build-a-shell-command-gate-in-typescript-20je"
  },
  "original_language": "en",
  "account": "Title: Your Agent's Allowlist Bug: Building a Shell Command Gate in TypeScript\n\nThe article explores the consequences of a bug in the allowlist of an AI agent's command parsing system. The issue affects multiple products, with four CVE numbers assigned in September 2026 alone. This bug arises from the parser's inability to correctly interpret PowerShell commands and Git commands, leading to unauthorized execution of sensitive commands.\n\nThe article presents a TypeScript-based solution called \"tiny-shell-gate\" to address this vulnerability. The gate is designed to enforce strict command parsing rules, ensuring that only approved commands are executed. It achieves this by rejecting any arguments not explicitly approved, refusing syntax that the gate cannot model, and splitting the remaining input on control operators before matching each segment exactly.\n\nThe author demonstrates the effectiveness of the gate using a poisoned README file containing various commands. The naive gate, which does not employ the gate's strict parsing rules, executes seven commands from the README. In contrast, the new gate allows two commands, asks about two more, and denies the remaining three, showcasing its ability to maintain security without requiring an API key or executing any real models.\n\nThe article emphasizes the importance of building a gate that refuses input it cannot parse, rather than attempting to build a smarter allowlist. By implementing this approach, developers can mitigate the risk of unauthorized command execution, thereby enhancing the overall security of their systems.",
  "summary": "You click \"always allow\" on git status . You think you approved a command. Your agent's harness thinks you approved a program. Your shell thinks nothing at all. It just runs whatever string it gets. Three parties. Three different ideas of what you said yes to. In September, that gap got four CVE numbers. Sep 1, 2026. NVD published CVE-2026-19591 . OpenAI's Codex CLI and Desktop \"misclassified…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}