| { |
| "$schema": "http://json-schema.org/draft-07/schema#", |
| "definitions": { |
| "AdditionalFileSystemPermissions": { |
| "properties": { |
| "entries": { |
| "items": { |
| "$ref": "#/definitions/FileSystemSandboxEntry" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| }, |
| "globScanMaxDepth": { |
| "format": "uint", |
| "minimum": 1.0, |
| "type": [ |
| "integer", |
| "null" |
| ] |
| }, |
| "read": { |
| "description": "This will be removed in favor of `entries`.", |
| "items": { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| }, |
| "write": { |
| "description": "This will be removed in favor of `entries`.", |
| "items": { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| } |
| }, |
| "type": "object" |
| }, |
| "AdditionalNetworkPermissions": { |
| "properties": { |
| "enabled": { |
| "type": [ |
| "boolean", |
| "null" |
| ] |
| } |
| }, |
| "type": "object" |
| }, |
| "AdditionalPermissionProfile": { |
| "properties": { |
| "fileSystem": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/AdditionalFileSystemPermissions" |
| }, |
| { |
| "type": "null" |
| } |
| ] |
| }, |
| "network": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/AdditionalNetworkPermissions" |
| }, |
| { |
| "type": "null" |
| } |
| ], |
| "description": "Partial overlay used for per-command permission requests." |
| } |
| }, |
| "type": "object" |
| }, |
| "CommandAction": { |
| "oneOf": [ |
| { |
| "properties": { |
| "command": { |
| "type": "string" |
| }, |
| "name": { |
| "type": "string" |
| }, |
| "path": { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| "type": { |
| "enum": [ |
| "read" |
| ], |
| "title": "ReadCommandActionType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "command", |
| "name", |
| "path", |
| "type" |
| ], |
| "title": "ReadCommandAction", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "command": { |
| "type": "string" |
| }, |
| "path": { |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "type": { |
| "enum": [ |
| "listFiles" |
| ], |
| "title": "ListFilesCommandActionType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "command", |
| "type" |
| ], |
| "title": "ListFilesCommandAction", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "command": { |
| "type": "string" |
| }, |
| "path": { |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "query": { |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "type": { |
| "enum": [ |
| "search" |
| ], |
| "title": "SearchCommandActionType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "command", |
| "type" |
| ], |
| "title": "SearchCommandAction", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "command": { |
| "type": "string" |
| }, |
| "type": { |
| "enum": [ |
| "unknown" |
| ], |
| "title": "UnknownCommandActionType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "command", |
| "type" |
| ], |
| "title": "UnknownCommandAction", |
| "type": "object" |
| } |
| ] |
| }, |
| "CommandExecutionApprovalDecision": { |
| "oneOf": [ |
| { |
| "description": "User approved the command.", |
| "enum": [ |
| "accept" |
| ], |
| "type": "string" |
| }, |
| { |
| "description": "User approved the command and future prompts in the same session-scoped approval cache should run without prompting.", |
| "enum": [ |
| "acceptForSession" |
| ], |
| "type": "string" |
| }, |
| { |
| "additionalProperties": false, |
| "description": "User approved the command, and wants to apply the proposed execpolicy amendment so future matching commands can run without prompting.", |
| "properties": { |
| "acceptWithExecpolicyAmendment": { |
| "properties": { |
| "execpolicy_amendment": { |
| "items": { |
| "type": "string" |
| }, |
| "type": "array" |
| } |
| }, |
| "required": [ |
| "execpolicy_amendment" |
| ], |
| "type": "object" |
| } |
| }, |
| "required": [ |
| "acceptWithExecpolicyAmendment" |
| ], |
| "title": "AcceptWithExecpolicyAmendmentCommandExecutionApprovalDecision", |
| "type": "object" |
| }, |
| { |
| "additionalProperties": false, |
| "description": "User chose a persistent network policy rule (allow/deny) for this host.", |
| "properties": { |
| "applyNetworkPolicyAmendment": { |
| "properties": { |
| "network_policy_amendment": { |
| "$ref": "#/definitions/NetworkPolicyAmendment" |
| } |
| }, |
| "required": [ |
| "network_policy_amendment" |
| ], |
| "type": "object" |
| } |
| }, |
| "required": [ |
| "applyNetworkPolicyAmendment" |
| ], |
| "title": "ApplyNetworkPolicyAmendmentCommandExecutionApprovalDecision", |
| "type": "object" |
| }, |
| { |
| "description": "User denied the command. The agent will continue the turn.", |
| "enum": [ |
| "decline" |
| ], |
| "type": "string" |
| }, |
| { |
| "description": "User denied the command. The turn will also be immediately interrupted.", |
| "enum": [ |
| "cancel" |
| ], |
| "type": "string" |
| } |
| ] |
| }, |
| "CommandExecutionApprovalKind": { |
| "description": "Distinguishes a command approval from input sent to an existing terminal.", |
| "enum": [ |
| "command", |
| "writeStdin" |
| ], |
| "type": "string" |
| }, |
| "FileSystemAccessMode": { |
| "enum": [ |
| "read", |
| "write", |
| "deny" |
| ], |
| "type": "string" |
| }, |
| "FileSystemPath": { |
| "oneOf": [ |
| { |
| "properties": { |
| "path": { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| "type": { |
| "enum": [ |
| "path" |
| ], |
| "title": "PathFileSystemPathType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "path", |
| "type" |
| ], |
| "title": "PathFileSystemPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "pattern": { |
| "type": "string" |
| }, |
| "type": { |
| "enum": [ |
| "glob_pattern" |
| ], |
| "title": "GlobPatternFileSystemPathType", |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "pattern", |
| "type" |
| ], |
| "title": "GlobPatternFileSystemPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "type": { |
| "enum": [ |
| "special" |
| ], |
| "title": "SpecialFileSystemPathType", |
| "type": "string" |
| }, |
| "value": { |
| "$ref": "#/definitions/FileSystemSpecialPath" |
| } |
| }, |
| "required": [ |
| "type", |
| "value" |
| ], |
| "title": "SpecialFileSystemPath", |
| "type": "object" |
| } |
| ] |
| }, |
| "FileSystemSandboxEntry": { |
| "properties": { |
| "access": { |
| "$ref": "#/definitions/FileSystemAccessMode" |
| }, |
| "path": { |
| "$ref": "#/definitions/FileSystemPath" |
| } |
| }, |
| "required": [ |
| "access", |
| "path" |
| ], |
| "type": "object" |
| }, |
| "FileSystemSpecialPath": { |
| "oneOf": [ |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "root" |
| ], |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "kind" |
| ], |
| "title": "RootFileSystemSpecialPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "minimal" |
| ], |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "kind" |
| ], |
| "title": "MinimalFileSystemSpecialPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "project_roots" |
| ], |
| "type": "string" |
| }, |
| "subpath": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| { |
| "type": "null" |
| } |
| ] |
| } |
| }, |
| "required": [ |
| "kind" |
| ], |
| "title": "KindFileSystemSpecialPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "tmpdir" |
| ], |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "kind" |
| ], |
| "title": "TmpdirFileSystemSpecialPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "slash_tmp" |
| ], |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "kind" |
| ], |
| "title": "SlashTmpFileSystemSpecialPath", |
| "type": "object" |
| }, |
| { |
| "properties": { |
| "kind": { |
| "enum": [ |
| "unknown" |
| ], |
| "type": "string" |
| }, |
| "path": { |
| "type": "string" |
| }, |
| "subpath": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| { |
| "type": "null" |
| } |
| ] |
| } |
| }, |
| "required": [ |
| "kind", |
| "path" |
| ], |
| "type": "object" |
| } |
| ] |
| }, |
| "LegacyAppPathString": { |
| "type": "string" |
| }, |
| "NetworkApprovalContext": { |
| "properties": { |
| "host": { |
| "type": "string" |
| }, |
| "protocol": { |
| "$ref": "#/definitions/NetworkApprovalProtocol" |
| } |
| }, |
| "required": [ |
| "host", |
| "protocol" |
| ], |
| "type": "object" |
| }, |
| "NetworkApprovalProtocol": { |
| "enum": [ |
| "http", |
| "https", |
| "socks5Tcp", |
| "socks5Udp" |
| ], |
| "type": "string" |
| }, |
| "NetworkPolicyAmendment": { |
| "properties": { |
| "action": { |
| "$ref": "#/definitions/NetworkPolicyRuleAction" |
| }, |
| "host": { |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "action", |
| "host" |
| ], |
| "type": "object" |
| }, |
| "NetworkPolicyRuleAction": { |
| "enum": [ |
| "allow", |
| "deny" |
| ], |
| "type": "string" |
| } |
| }, |
| "properties": { |
| "approvalId": { |
| "description": "Unique identifier for this specific approval callback.\n\nFor regular shell/unified_exec approvals, this is null.\n\nFor zsh-exec-bridge subcommand approvals, multiple callbacks can belong to one parent `itemId`, so `approvalId` is a distinct opaque callback id (a UUID) used to disambiguate routing. Stdin approvals also use a distinct callback id; inspect `kind` to distinguish them.", |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "command": { |
| "description": "The command to be executed.", |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "commandActions": { |
| "description": "Best-effort parsed command actions for friendly display.", |
| "items": { |
| "$ref": "#/definitions/CommandAction" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| }, |
| "cwd": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/LegacyAppPathString" |
| }, |
| { |
| "type": "null" |
| } |
| ], |
| "description": "The command's working directory." |
| }, |
| "environmentId": { |
| "default": null, |
| "description": "Environment in which the command will run.", |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "itemId": { |
| "type": "string" |
| }, |
| "kind": { |
| "allOf": [ |
| { |
| "$ref": "#/definitions/CommandExecutionApprovalKind" |
| } |
| ], |
| "default": "command", |
| "description": "Kind of action under review. Defaults to `command` for older servers." |
| }, |
| "networkApprovalContext": { |
| "anyOf": [ |
| { |
| "$ref": "#/definitions/NetworkApprovalContext" |
| }, |
| { |
| "type": "null" |
| } |
| ], |
| "description": "Optional context for a managed-network approval prompt." |
| }, |
| "proposedExecpolicyAmendment": { |
| "description": "Optional proposed execpolicy amendment to allow similar commands without prompting.", |
| "items": { |
| "type": "string" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| }, |
| "proposedNetworkPolicyAmendments": { |
| "description": "Optional proposed network policy amendments (allow/deny host) for future requests.", |
| "items": { |
| "$ref": "#/definitions/NetworkPolicyAmendment" |
| }, |
| "type": [ |
| "array", |
| "null" |
| ] |
| }, |
| "reason": { |
| "description": "Optional explanatory reason (e.g. request for network access).", |
| "type": [ |
| "string", |
| "null" |
| ] |
| }, |
| "startedAtMs": { |
| "description": "Unix timestamp (in milliseconds) when this approval request started.", |
| "format": "int64", |
| "type": "integer" |
| }, |
| "threadId": { |
| "type": "string" |
| }, |
| "turnId": { |
| "type": "string" |
| } |
| }, |
| "required": [ |
| "itemId", |
| "startedAtMs", |
| "threadId", |
| "turnId" |
| ], |
| "title": "CommandExecutionRequestApprovalParams", |
| "type": "object" |
| } |