GenAI CLI Started with Unsafe Permission Bypass
Identifies GenAI agent CLIs started with permission-bypass or auto-approval flags that disable human-in-the-loop guardrails. These modes are intended for isolated sandboxes but are frequently misused on internet-connected developer workstations, allowing prompt injection, compromised dependencies, or malicious skills to execute commands, modify files, or reach sensitive paths without confirmation.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/06/24"
3integration = ["endpoint"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Identifies GenAI agent CLIs started with permission-bypass or auto-approval flags that disable human-in-the-loop
11guardrails. These modes are intended for isolated sandboxes but are frequently misused on internet-connected developer
12workstations, allowing prompt injection, compromised dependencies, or malicious skills to execute commands, modify
13files, or reach sensitive paths without confirmation.
14"""
15from = "now-9m"
16index = ["logs-endpoint.events.process-*"]
17language = "eql"
18license = "Elastic License v2"
19name = "GenAI CLI Started with Unsafe Permission Bypass"
20note = """## Triage and analysis
21
22### Investigating GenAI CLI Started with Unsafe Permission Bypass
23
24GenAI coding agents normally prompt before running shell commands or editing files. Vendor-supplied bypass flags remove
25those controls entirely or auto-approve all tool calls. On a networked host this materially increases blast radius from
26prompt injection, poisoned MCP servers, malicious project configs, and autonomous agent workflows.
27
28### Possible investigation steps
29
30- Identify which GenAI tool and bypass flag were used from `process.command_line` and `process.executable`.
31- Determine whether the session was intentional (CI/CD, isolated lab VM) or an interactive developer workstation.
32- Review child processes spawned after startup for credential access, network exfiltration, or persistence.
33- Check for recent GenAI config changes (MCP servers, skills, `.claude/settings.json`, `~/.codex/config.toml`).
34- Correlate with other GenAI-related alerts on the same host and user.
35
36### False positive analysis
37
38- Deliberate use in approved sandbox/CI images with no outbound network access.
39- Internal automation scripts that wrap GenAI CLIs with bypass flags; scope exceptions by host or user group.
40- Each matching process start produces one alert; habitual bypass use in CI or developer workflows may need host or user exceptions.
41
42### Response and remediation
43
44- Remove bypass flags from scripts, shell profiles, and CI job definitions; use default or plan-only permission modes.
45- Rotate API keys and cloud credentials accessible to the user account that ran the agent.
46- Audit GenAI tool configs and MCP servers loaded during the session.
47- Restrict GenAI agent usage policies to disallow permission bypass on production endpoints.
48"""
49references = [
50 "https://code.claude.com/docs/en/permission-modes",
51 "https://developers.openai.com/codex/cli/reference",
52 "https://developers.openai.com/codex/agent-approvals-security",
53 "https://google-gemini.github.io/gemini-cli/docs/get-started/configuration.html",
54 "https://specterops.io/blog/2025/11/21/an-evening-with-claude-code/",
55]
56risk_score = 47
57rule_id = "c1326e45-6d3c-4a2d-9882-606a0c310299"
58severity = "medium"
59tags = [
60 "Domain: Endpoint",
61 "OS: Linux",
62 "OS: macOS",
63 "OS: Windows",
64 "Use Case: Threat Detection",
65 "Tactic: Defense Evasion",
66 "Data Source: Elastic Defend",
67 "Resources: Investigation Guide",
68 "Domain: LLM",
69 "Noise: High",
70 "Performance: Normal",
71 "Profile: Aggressive",
72 "Threat: Unauthorized AI Usage",
73 "Rule Type: Event Correlation (EQL)",
74 "Platform: Windows",
75 "Platform: Linux",
76 "Platform: macOS",
77 "Domain: GenAI",
78]
79timestamp_override = "event.ingested"
80type = "eql"
81
82query = '''
83process where event.type == "start" and event.action in ("exec", "start") and
84(
85 (
86 process.args in (
87 "--dangerously-skip-permissions",
88 "--allow-dangerously-skip-permissions",
89 "--permission-mode=bypassPermissions"
90 ) or
91 (process.args == "--permission-mode" and process.args == "bypassPermissions")
92 ) and
93 (
94 process.name in ("claude", "claude.exe") or
95 process.executable : (
96 "*/.local/share/claude/versions/*",
97 "*/.claude/downloads/*",
98 "*Caskroom/claude-code/*",
99 "*\\Claude\\versions\\*"
100 ) or
101 (process.name in ("node", "node.exe") and process.args : "*@anthropic-ai/claude-code*")
102 )
103) or
104(
105 (
106 process.args in ("--dangerously-bypass-approvals-and-sandbox", "--full-auto", "--yolo") or
107 process.command_line : (
108 "* -s danger-full-access*",
109 "*--sandbox danger-full-access*",
110 "*--sandbox=danger-full-access*",
111 "*--ask-for-approval never*",
112 "*--ask-for-approval=never*"
113 )
114 ) and
115 (
116 process.name in (
117 "codex", "codex.exe", "codex-exec",
118 "codex-aarch64-apple-darwin", "codex-x86_64-apple-darwin",
119 "codex-linux-arm64", "codex-linux-x64"
120 ) or
121 (process.name in ("node", "node.exe") and process.args : ("*@openai/codex*", "*/codex", "*\\codex*"))
122 )
123) or
124(
125 (
126 process.args in ("--yolo", "-y") or
127 (process.args == "--approval-mode" and process.args == "yolo") or
128 process.args == "--approval-mode=yolo"
129 ) and
130 (
131 process.name in ("gemini", "gemini-cli", "gemini.exe", "gemini-cli.exe") or
132 (process.name in ("node", "node.exe") and process.args : ("*@google/gemini-cli*", "*/gemini", "*\\gemini*"))
133 )
134) or
135(
136 (
137 process.args in (
138 "--yolo",
139 "--autopilot",
140 "--allow-all",
141 "--allow-all-tools",
142 "--allow-all-paths",
143 "--allow-all-urls"
144 )
145 ) and
146 (
147 process.name in ("copilot", "copilot.exe") or
148 (process.name in ("node", "node.exe") and process.args : ("*@github/copilot*", "*/copilot", "*\\copilot*"))
149 )
150) or
151(
152 process.args == "--dangerously-skip-permissions" and
153 (
154 process.name in ("opencode", "opencode.exe", ".opencode") or
155 process.executable : ("*opencode-ai*", "*\\.opencode*") or
156 (process.name in ("node", "node.exe") and process.args : ("*opencode-ai*", "*/opencode", "*\\opencode*"))
157 )
158)
159'''
160
161
162[[rule.threat]]
163framework = "MITRE ATT&CK"
164[[rule.threat.technique]]
165id = "T1562"
166name = "Impair Defenses"
167reference = "https://attack.mitre.org/techniques/T1562/"
168[[rule.threat.technique.subtechnique]]
169id = "T1562.001"
170name = "Disable or Modify Tools"
171reference = "https://attack.mitre.org/techniques/T1562/001/"
172
173
174
175[rule.threat.tactic]
176id = "TA0005"
177name = "Defense Evasion"
178reference = "https://attack.mitre.org/tactics/TA0005/"
Triage and analysis
Investigating GenAI CLI Started with Unsafe Permission Bypass
GenAI coding agents normally prompt before running shell commands or editing files. Vendor-supplied bypass flags remove those controls entirely or auto-approve all tool calls. On a networked host this materially increases blast radius from prompt injection, poisoned MCP servers, malicious project configs, and autonomous agent workflows.
Possible investigation steps
- Identify which GenAI tool and bypass flag were used from
process.command_lineandprocess.executable. - Determine whether the session was intentional (CI/CD, isolated lab VM) or an interactive developer workstation.
- Review child processes spawned after startup for credential access, network exfiltration, or persistence.
- Check for recent GenAI config changes (MCP servers, skills,
.claude/settings.json,~/.codex/config.toml). - Correlate with other GenAI-related alerts on the same host and user.
False positive analysis
- Deliberate use in approved sandbox/CI images with no outbound network access.
- Internal automation scripts that wrap GenAI CLIs with bypass flags; scope exceptions by host or user group.
- Each matching process start produces one alert; habitual bypass use in CI or developer workflows may need host or user exceptions.
Response and remediation
- Remove bypass flags from scripts, shell profiles, and CI job definitions; use default or plan-only permission modes.
- Rotate API keys and cloud credentials accessible to the user account that ran the agent.
- Audit GenAI tool configs and MCP servers loaded during the session.
- Restrict GenAI agent usage policies to disallow permission bypass on production endpoints.
References
Related rules
- Execution via OpenClaw Agent
- GenAI Process Compiling or Generating Executables
- GenAI Process Performing Encoding/Chunking Prior to Network Activity
- GenAI Process Accessing Sensitive Files
- Connection to Common Large Language Model Endpoints