# dsh-automode bundle patch (v0.5.0) # # Inserts the plugin row + the auto-mode permission preset. # The preset appears in the permission picker next to read-only / # workspace-write / danger-full-access. - insert: - id: auto-mode name: '@log.li/dsh-automode' config: deny: - exfiltrat - 'curl\s+[^|]*\|\s*(?:ba)?sh' - 'wget\s+[^|]*\|\s*(?:ba)?sh' - authorized_keys - 'AWS_SECRET|PRIVATE KEY|-----BEGIN' - \.aws/credentials - '(?:^|[\s;&|("''])(?:trash|mv)\s+/(?:etc|usr|bin|sbin|var|System|Library|private/etc)(?:/|\s|$)' - 'docker\s+(volume\s+rm|system\s+prune|container\s+prune)' - '(?