Dangerous Shell Commands

Deny an AI agent shell tool when its command contains text you listed, such as rm -rf. Other commands still run. This is not a sandbox.

Real-Time(Preventive)Checked before the call runs, so it can stop it

An ops agent has a shell tool. Most commands are fine. A few should never run. This policy reads the command text the agent passed and denies the call if it contains a string you listed.

Runs On
The SDK only
You Set
The shell tool names, and the text patterns to block, such as rm -rf.
Your Agent Sends
The command text, in a field named command, cmd, argv, or code

What Happens

With rm -rf on the list and Block on:

Command the agent sendsResult
rm -rf /tmp/cacheDenied. The shell function does not run.
lsRuns.
No command text on the callThe rule is skipped and the tool still runs. The match is recorded as a warning.

Set It Up

  1. In the app, open Policies and click Create Policy.
  2. Choose Dangerous Shell Commands.
  3. Under Block If Command Contains, add the text to stop, such as rm -rf.
  4. Under Applies To, list the tool name, usually shell.
  5. Set the mode to Block, then click Activate Policy.
  6. Wrap the agent with govern() and mark the shell function as a tool.

Not A Sandbox

This policy does not sit on the operating system and does not block a terminal you did not instrument. It compares the text your agent passed to the strings you listed. A different tool that happens to mention rm -rf in a search query is not denied.

Good To Know

  • Traccia does not run commands. It only decides whether your function may run.
  • This policy does not apply on the Gateway.

A worked example is in Stop A Dangerous Tool.

Next Steps

© 2026 Traccia.