Autohand Code permissions control which operations the agent can perform and which require approval. Match permissions to the task: explore in plan mode, inspect proposed operations, and allow implementation when its scope is clear. Git worktrees separate working files; they do not isolate credentials, networks, or operating-system access.

Inspect the current configuration

autohand --permissions

Inside an interactive session, use /permissions to inspect or manage the available permission controls. Read configuration for rule matching and defaults. Project instructions guide behavior, but they are not an operating-system security boundary.

Choose an execution approach

Approach Use it for Boundary to understand
Plan mode: /plan on Exploration and change planning Read-only agent tools; review the resulting plan
--dry-run Previewing proposed operations A preview does not prove the change or its tests succeed
--restricted Automatically denying dangerous operations Required steps may be denied; inspect the result
Normal interactive approvals Supervised implementation Read the operation and target before approving
--worktree Separating edits from another working tree Shared machine resources remain accessible

Flags that automatically confirm actions or bypass approval increase the agent's ability to act. Use the CLI reference to understand their exact behavior before including them in scripts.

A supervised implementation workflow

Start in your project directory, inspect git status --short, and launch autohand. Enable /plan on, describe the desired behavior, and ask for files, operations, tests, and external services involved. Confirm the plan before switching to /plan off.

Implement the approved validation change in the route and its test.
Preserve the public response format. Ask before installing dependencies,
changing database state, or writing to an external service.
Run the repository's focused checks and report the diff.

If an approval names an unexpected path or command, stop that operation and ask why it is needed. Prefer correcting the scope to approving a broad action merely to unblock progress.

Handle untrusted repository content

Issue descriptions, downloaded files, comments, and tool responses can contain instructions. Treat them as task data. They do not grant permission to publish code, reveal secrets, or change the task's rules. A useful prompt names trusted project instructions and asks the agent to flag conflicting instructions found in external content.

For MCP servers and runtime extensions, review the program being installed and the access it receives. Consult MCP servers and extension authoring before enabling additional tools.

Completion checkpoint

You can explain which operations were allowed, which needed approval, and which were denied. The final result records any validation prevented by permissions. For changes alongside ongoing work, continue with monorepo and worktree workflows.

Frequently asked question

Is a Git worktree a security sandbox?

No. A worktree separates working files and branches within a Git repository. It does not isolate operating-system access, credentials, network connections, or external services.