Agent execution and permissions
Some agent tools run real programs on your computer. The main one is the shell tool, which lets an agent run command-line programs, for example to install a project's dependencies, run a build, or start a local development server for something it just wrote.
Because these commands run on your machine, Verzeta only lets agents run programs you have allowed. This page explains that allow-list, how to change it, and the other kinds of tools agents can use.
Each command may run for up to two minutes. Longer programs, such as a development server, can be started in the background; up to four can run at once.
The shell command allow-list
Verzeta keeps a list of the programs an agent is allowed to run. When an agent tries to run a command, Verzeta looks at the first word (the program name). If it is on the list, the command runs; if not, the command is refused and the agent is told the program is not allowed.
Out of the box the list on Linux already contains the everyday tools a coding agent needs, including:
- File inspection tools such as
ls,cat,grep,find. - Language runtimes and package managers such as
python,node,npm,pip. - Version control and build tools such as
git,make,cmake. - Network fetch tools
curlandwget(useful for checking a local server an agent has started). killandpkill, to stop a background process.
On Windows the default list uses the Windows equivalents instead, such as
dir, type, findstr and where, plus python, git, cmake, ninja
and curl. Add others such as node or npm yourself.
Changing the list
Open Settings and find the Execution & Permissions card, then select it to open the editor. There you can:
- See every allowed program as a chip.
- Add a program by typing its name and choosing Add.
- Remove a program by selecting the remove button on its chip. You can remove any program, including one that came as a default.
- Restore to Default to bring the full built-in list back, including anything you removed.
Changes take effect immediately and apply to every agent and every conversation.
Safety
You are responsible for the programs you allow. An agent can run any allowed program, so only add tools you are comfortable letting an agent use.
Two protections stay in place no matter what is on the list:
- Dangerous command patterns are always blocked. For example, deleting
files recursively (
rm -r), running commands as a superuser (sudo), formatting a disk, writing to system paths, shutting down the computer, or downloading a script and piping it straight into a shell are refused even if the program itself is allowed. - Code that cannot be checked is refused. Piping text into a shell
(
... | bash,base64 -d | sh),evalof text built from variables, andbash -c "$VAR"run code nobody can inspect before it runs, so they are refused. Ordinary commands, pipes, loops, heredocs such aspython3 - <<'EOF'andbash -c 'literal commands'are not affected. - Commands start in the current project's folder. This is where relative
paths point. On its own it is not a sandbox: a command can still use
absolute paths or
cdelsewhere, with your user's permissions.
Write protection (optional)
The Write protection switch in the same editor is off by default. When you turn it on, commands agents run (and background processes they start) can still read files and run programs anywhere, but can only create, change or delete files in:
- the current project folder,
- temporary folders (
/tmpand your temp directory), - folders you add with Add folder.
Anything else, such as your home folder or system folders, is refused by the
operating system. The agent is told that write protection caused the refusal
and that retrying will not help, so it stops and asks you, for example whether
to save the file in the project folder instead. Package
caches are moved to a temporary folder so pip and npm keep working;
installing packages globally or with pip install --user will not, so have
agents use a virtual environment in the project instead.
Write protection uses the Landlock feature of the Linux kernel, so it needs no extra software and also works in the AppImage. It is not available on Windows or on Linux systems without Landlock; the switch is disabled there. It does not apply to commands you type yourself in the Terminal page.
If you remove every program from the list, agents will not be able to run any shell command until you add one back or choose Restore to Default.
Built-in tools, custom tools and MCP servers
Open Tools in the navigation bar to see every tool agents can use. Each tool has a switch to turn it on or off.
- Built-in: the tools that ship with Verzeta Studio.
- Custom: your own tools, added with Add Custom Tool. Each one runs a
Command Template, with
{{param_name}}replaced by the value the agent passes. The value is always inserted as plain text, quoted for where the placeholder sits (bare, inside"..."or inside'...'), so it can never add a command of its own. On Windows, values containing& | < > ^ % !or"are refused. The finished command goes through the dangerous-pattern check but not the allow-list (the template is yours), and runs in a shell with your user's permissions for up to the Time limit you set (30 seconds by default, at most 600). - MCP: tools from Model Context Protocol servers. Click Add MCP Server,
choose the Transport Type (stdio for a local program such as
npx,pythonoruvx, or SSE or Streamable HTTP for a server), and enter the command or URL. Once the server connects, its tools appear asserver:tooland can be turned on or off one by one.
Type /showtools or /showmcptools in a chat to see which tools that chat
can use. To limit the tools of one team member, use its tool whitelist (see
Multi-agent teams).