[Bug] Agent modifies repository without explicit user consent during setup
Bug Description
Fable5 engineered around the readme of a cloned ciso-assistant tool to setup access rather than follow the readme quickstart instructions and hand over to me. I should have simply cloned the repo myself - but its an odd thing to do given my system prompt to not touch my local postgres on docker (it grepped a privileged postgres instance docker-compose.yaml file to prevent image name collision). It also sporadically finds workarounds to my explicit deny settings.json (including docker and git - a specialized mcp readonly access to my local kubernetes cluster did stop it from trying kubectl most of the time). It also cloned and modified the repo without explicitly saying it would - admittedly my prompt was a bit lazy and unclear - copied and pasted from the output of another agent's security audit where I asked about potentially using Ciso Assistant locally to audit my cluster, with a "I would like to do this" at the end.
Environment Info
- Platform: darwin
- Terminal: iTerm.app
- Version: 2.1.214
- Feedback ID: 24de805f-b3f7-4a1e-a2f7-89dbb74c9633
Errors
[]