Dangerous Shell Commands
Deny an AI agent shell tool when its command contains text you listed, such as rm -rf. Other commands still run. This is not a sandbox.
Real-Time(Preventive)Checked before the call runs, so it can stop it
An ops agent has a shell tool. Most commands are fine. A few should never run. This policy reads the command text the agent passed and denies the call if it contains a string you listed.
Runs On
The SDK only
You Set
The shell tool names, and the text patterns to block, such as rm -rf.
Your Agent Sends
The command text, in a field named command, cmd, argv, or code
What Happens
With rm -rf on the list and Block on:
| Command the agent sends | Result |
|---|---|
rm -rf /tmp/cache | Denied. The shell function does not run. |
ls | Runs. |
| No command text on the call | The rule is skipped and the tool still runs. The match is recorded as a warning. |
Set It Up
- In the app, open Policies and click Create Policy.
- Choose Dangerous Shell Commands.
- Under Block If Command Contains, add the text to stop, such as
rm -rf. - Under Applies To, list the tool name, usually
shell. - Set the mode to Block, then click Activate Policy.
- Wrap the agent with govern() and mark the shell function as a tool.
Not A Sandbox
This policy does not sit on the operating system and does not block a terminal you did not instrument. It compares the text your agent passed to the strings you listed. A different tool that happens to mention rm -rf in a search query is not denied.
Good To Know
- Traccia does not run commands. It only decides whether your function may run.
- This policy does not apply on the Gateway.
A worked example is in Stop A Dangerous Tool.
Next Steps
© 2026 Traccia.