GenAI CLI Started with Unsafe Permission Bypass

Identifies GenAI agent CLIs started with permission-bypass or auto-approval flags that disable human-in-the-loop guardrails. These modes are intended for isolated sandboxes but are frequently misused on internet-connected developer workstations, allowing prompt injection, compromised dependencies, or malicious skills to execute commands, modify files, or reach sensitive paths without confirmation.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/06/24"
  3integration = ["endpoint"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Identifies GenAI agent CLIs started with permission-bypass or auto-approval flags that disable human-in-the-loop
 11guardrails. These modes are intended for isolated sandboxes but are frequently misused on internet-connected developer
 12workstations, allowing prompt injection, compromised dependencies, or malicious skills to execute commands, modify
 13files, or reach sensitive paths without confirmation.
 14"""
 15from = "now-9m"
 16index = ["logs-endpoint.events.process-*"]
 17language = "eql"
 18license = "Elastic License v2"
 19name = "GenAI CLI Started with Unsafe Permission Bypass"
 20note = """## Triage and analysis
 21
 22### Investigating GenAI CLI Started with Unsafe Permission Bypass
 23
 24GenAI coding agents normally prompt before running shell commands or editing files. Vendor-supplied bypass flags remove
 25those controls entirely or auto-approve all tool calls. On a networked host this materially increases blast radius from
 26prompt injection, poisoned MCP servers, malicious project configs, and autonomous agent workflows.
 27
 28### Possible investigation steps
 29
 30- Identify which GenAI tool and bypass flag were used from `process.command_line` and `process.executable`.
 31- Determine whether the session was intentional (CI/CD, isolated lab VM) or an interactive developer workstation.
 32- Review child processes spawned after startup for credential access, network exfiltration, or persistence.
 33- Check for recent GenAI config changes (MCP servers, skills, `.claude/settings.json`, `~/.codex/config.toml`).
 34- Correlate with other GenAI-related alerts on the same host and user.
 35
 36### False positive analysis
 37
 38- Deliberate use in approved sandbox/CI images with no outbound network access.
 39- Internal automation scripts that wrap GenAI CLIs with bypass flags; scope exceptions by host or user group.
 40- Each matching process start produces one alert; habitual bypass use in CI or developer workflows may need host or user exceptions.
 41
 42### Response and remediation
 43
 44- Remove bypass flags from scripts, shell profiles, and CI job definitions; use default or plan-only permission modes.
 45- Rotate API keys and cloud credentials accessible to the user account that ran the agent.
 46- Audit GenAI tool configs and MCP servers loaded during the session.
 47- Restrict GenAI agent usage policies to disallow permission bypass on production endpoints.
 48"""
 49references = [
 50    "https://code.claude.com/docs/en/permission-modes",
 51    "https://developers.openai.com/codex/cli/reference",
 52    "https://developers.openai.com/codex/agent-approvals-security",
 53    "https://google-gemini.github.io/gemini-cli/docs/get-started/configuration.html",
 54    "https://specterops.io/blog/2025/11/21/an-evening-with-claude-code/",
 55]
 56risk_score = 47
 57rule_id = "c1326e45-6d3c-4a2d-9882-606a0c310299"
 58severity = "medium"
 59tags = [
 60    "Domain: Endpoint",
 61    "OS: Linux",
 62    "OS: macOS",
 63    "OS: Windows",
 64    "Use Case: Threat Detection",
 65    "Tactic: Defense Evasion",
 66    "Data Source: Elastic Defend",
 67    "Resources: Investigation Guide",
 68    "Domain: LLM",
 69    "Noise: High",
 70    "Performance: Normal",
 71    "Profile: Aggressive",
 72    "Threat: Unauthorized AI Usage",
 73    "Rule Type: Event Correlation (EQL)",
 74    "Platform: Windows",
 75    "Platform: Linux",
 76    "Platform: macOS",
 77    "Domain: GenAI",
 78]
 79timestamp_override = "event.ingested"
 80type = "eql"
 81
 82query = '''
 83process where event.type == "start" and event.action in ("exec", "start") and
 84(
 85  (
 86    process.args in (
 87      "--dangerously-skip-permissions",
 88      "--allow-dangerously-skip-permissions",
 89      "--permission-mode=bypassPermissions"
 90    ) or
 91    (process.args == "--permission-mode" and process.args == "bypassPermissions")
 92  ) and
 93  (
 94    process.name in ("claude", "claude.exe") or
 95    process.executable : (
 96      "*/.local/share/claude/versions/*",
 97      "*/.claude/downloads/*",
 98      "*Caskroom/claude-code/*",
 99      "*\\Claude\\versions\\*"
100    ) or
101    (process.name in ("node", "node.exe") and process.args : "*@anthropic-ai/claude-code*")
102  )
103) or
104(
105  (
106    process.args in ("--dangerously-bypass-approvals-and-sandbox", "--full-auto", "--yolo") or
107    process.command_line : (
108      "* -s danger-full-access*",
109      "*--sandbox danger-full-access*",
110      "*--sandbox=danger-full-access*",
111      "*--ask-for-approval never*",
112      "*--ask-for-approval=never*"
113    )
114  ) and
115  (
116    process.name in (
117      "codex", "codex.exe", "codex-exec",
118      "codex-aarch64-apple-darwin", "codex-x86_64-apple-darwin",
119      "codex-linux-arm64", "codex-linux-x64"
120    ) or
121    (process.name in ("node", "node.exe") and process.args : ("*@openai/codex*", "*/codex", "*\\codex*"))
122  )
123) or
124(
125  (
126    process.args in ("--yolo", "-y") or
127    (process.args == "--approval-mode" and process.args == "yolo") or
128    process.args == "--approval-mode=yolo"
129  ) and
130  (
131    process.name in ("gemini", "gemini-cli", "gemini.exe", "gemini-cli.exe") or
132    (process.name in ("node", "node.exe") and process.args : ("*@google/gemini-cli*", "*/gemini", "*\\gemini*"))
133  )
134) or
135(
136  (
137    process.args in (
138      "--yolo",
139      "--autopilot",
140      "--allow-all",
141      "--allow-all-tools",
142      "--allow-all-paths",
143      "--allow-all-urls"
144    )
145  ) and
146  (
147    process.name in ("copilot", "copilot.exe") or
148    (process.name in ("node", "node.exe") and process.args : ("*@github/copilot*", "*/copilot", "*\\copilot*"))
149  )
150) or
151(
152  process.args == "--dangerously-skip-permissions" and
153  (
154    process.name in ("opencode", "opencode.exe", ".opencode") or
155    process.executable : ("*opencode-ai*", "*\\.opencode*") or
156    (process.name in ("node", "node.exe") and process.args : ("*opencode-ai*", "*/opencode", "*\\opencode*"))
157  )
158)
159'''
160
161
162[[rule.threat]]
163framework = "MITRE ATT&CK"
164[[rule.threat.technique]]
165id = "T1562"
166name = "Impair Defenses"
167reference = "https://attack.mitre.org/techniques/T1562/"
168[[rule.threat.technique.subtechnique]]
169id = "T1562.001"
170name = "Disable or Modify Tools"
171reference = "https://attack.mitre.org/techniques/T1562/001/"
172
173
174
175[rule.threat.tactic]
176id = "TA0005"
177name = "Defense Evasion"
178reference = "https://attack.mitre.org/tactics/TA0005/"

Triage and analysis

Investigating GenAI CLI Started with Unsafe Permission Bypass

GenAI coding agents normally prompt before running shell commands or editing files. Vendor-supplied bypass flags remove those controls entirely or auto-approve all tool calls. On a networked host this materially increases blast radius from prompt injection, poisoned MCP servers, malicious project configs, and autonomous agent workflows.

Possible investigation steps

  • Identify which GenAI tool and bypass flag were used from process.command_line and process.executable.
  • Determine whether the session was intentional (CI/CD, isolated lab VM) or an interactive developer workstation.
  • Review child processes spawned after startup for credential access, network exfiltration, or persistence.
  • Check for recent GenAI config changes (MCP servers, skills, .claude/settings.json, ~/.codex/config.toml).
  • Correlate with other GenAI-related alerts on the same host and user.

False positive analysis

  • Deliberate use in approved sandbox/CI images with no outbound network access.
  • Internal automation scripts that wrap GenAI CLIs with bypass flags; scope exceptions by host or user group.
  • Each matching process start produces one alert; habitual bypass use in CI or developer workflows may need host or user exceptions.

Response and remediation

  • Remove bypass flags from scripts, shell profiles, and CI job definitions; use default or plan-only permission modes.
  • Rotate API keys and cloud credentials accessible to the user account that ran the agent.
  • Audit GenAI tool configs and MCP servers loaded during the session.
  • Restrict GenAI agent usage policies to disallow permission bypass on production endpoints.

References

Related rules

to-top