Skip to content

[Security Bug] Subagent permissions not enforced - configured restrictions ignored #7474

Description

@randomm

Description

Subagents spawned via the task tool completely ignore agent permission configurations in > v1.0.200. Regardless of what restrictions are defined in opencode.json, subagents have unrestricted access to all tools.

Example

Agent configured with restricted bash access:

"permission": {
  "bash": {
    "git*": "allow",
    "*": "deny"
  }
}

Expected: Subagent can only run git commands
Actual: Subagent can run ANY bash command - restrictions ignored entirely

Root Cause

  1. SessionPrompt.prompt() tools parameter replaces session permissions instead of merging
  2. ToolRegistry.tools() doesn't filter tools by agent permission rules
  3. Subagents inherit no permission restrictions from parent agent config

Impact

Security - All agent permission configurations are effectively useless. Any subagent has full unrestricted access.

Fix

PR #7473 addresses this by:

  • Removing tools parameter override in task.ts
  • Adding permission filtering to ToolRegistry
  • Ensuring proper permission merge order

Related

Related to #6527, #5894, #3808

Activity

  1. github-actions commented on Jan 9, 2026

    @github-actions
    Contributor

    This issue might be a duplicate of or closely related to existing issues. Please check:

    Feel free to ignore if your specific case requires a separate track.

  2. randomm commented on Jan 9, 2026

    @randomm
    Author

    So just commenting still briefly: I have been stuck on 1.0.200 with my rather convoluted agent > subagent setup that relies on permissions working. Sometimes subagents go off rails if permissions do not work.

    Thus, today opencode/claude/me submitted the PR. Hopefully it is helpful!!

  3. evanreichard commented on Jan 10, 2026

    @evanreichard

    @randomm - can you try moving "*": "deny" so its the first directive. I was having the same issue and that seemed to fix it for me.

  4. randomm commented on Jan 10, 2026

    @randomm
    Author

    The subagents got a free for all regardless. The linked PR fixes this but having the deny as the first line is still necessary

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions