Verzeta

Agent execution and permissions

Some agent tools run real programs on your computer. The main one is the shell tool, which lets an agent run command-line programs, for example to install a project's dependencies, run a build, or start a local development server for something it just wrote.

Because these commands run on your machine, Verzeta only lets agents run programs you have allowed. This page explains that allow-list, how to change it, and the other kinds of tools agents can use.

Each command may run for up to two minutes. Longer programs, such as a development server, can be started in the background; up to four can run at once.

The shell command allow-list

Verzeta keeps a list of the programs an agent is allowed to run. When an agent tries to run a command, Verzeta looks at the first word (the program name). If it is on the list, the command runs; if not, the command is refused and the agent is told the program is not allowed.

Out of the box the list on Linux already contains the everyday tools a coding agent needs, including:

On Windows the default list uses the Windows equivalents instead, such as dir, type, findstr and where, plus python, git, cmake, ninja and curl. Add others such as node or npm yourself.

Changing the list

Open Settings and find the Execution & Permissions card, then select it to open the editor. There you can:

Changes take effect immediately and apply to every agent and every conversation.

Safety

You are responsible for the programs you allow. An agent can run any allowed program, so only add tools you are comfortable letting an agent use.

Two protections stay in place no matter what is on the list:

Write protection (optional)

The Write protection switch in the same editor is off by default. When you turn it on, commands agents run (and background processes they start) can still read files and run programs anywhere, but can only create, change or delete files in:

Anything else, such as your home folder or system folders, is refused by the operating system. The agent is told that write protection caused the refusal and that retrying will not help, so it stops and asks you, for example whether to save the file in the project folder instead. Package caches are moved to a temporary folder so pip and npm keep working; installing packages globally or with pip install --user will not, so have agents use a virtual environment in the project instead.

Write protection uses the Landlock feature of the Linux kernel, so it needs no extra software and also works in the AppImage. It is not available on Windows or on Linux systems without Landlock; the switch is disabled there. It does not apply to commands you type yourself in the Terminal page.

If you remove every program from the list, agents will not be able to run any shell command until you add one back or choose Restore to Default.

Built-in tools, custom tools and MCP servers

Open Tools in the navigation bar to see every tool agents can use. Each tool has a switch to turn it on or off.

Type /showtools or /showmcptools in a chat to see which tools that chat can use. To limit the tools of one team member, use its tool whitelist (see Multi-agent teams).

Verzeta Studio guides