--- title: "Action Safety" description: "Review potentially dangerous actions before they execute" --- Action safety is enabled by default and is independent of scan depth. `quick`, `standard`, and `deep` control coverage; guarded review controls which effects may be executed. ```bash strix --target https://example.test ``` Guarded review permits non-destructive interaction after contextual review, including injection probes, reconnaissance, enumeration, and fuzzing. Actions judged destructive or persistent are blocked. ## Disabling Safety Use the explicit dangerous opt-out only when external containment makes it necessary: ```bash strix --target https://example.test --dangerously-disable-safety ``` This disables both action review and workspace isolation. Local directories are mounted live and writable. A run created with safety disabled requires the flag again when resumed; a guarded run cannot be downgraded while resuming. ## Contextual Review Before an ambiguous shell or browser action executes, Strix compiles a frozen evidence packet containing the effective command, target scope, relevant script source and imports, prior tool-call evidence, browser snapshot context, and workspace persistence details. The safety model may decide immediately or make exactly one `run_inspection` tool call. That call runs a Python standard-library analysis script in a separate networkless, read-only container over the frozen evidence. If the tool is used, the model's next response must be the final decision. The review is bounded to at most two model turns and one optional inspection call. Timeouts, malformed decisions, a second tool call, incomplete evidence, and reviewer failures fail closed. In the interactive TUI, the reviewer can defer when complete evidence still leaves genuine ambiguity about whether an exact action is dangerous. Strix then pauses that tool call and asks the user to approve or deny it. Denial is selected by default, Escape denies, and the request waits until it is answered, the agent is stopped, or Strix exits. Approval applies only to the frozen call shown in the prompt; actions too large to display exactly must be split into smaller tool calls. Deterministic blocks, incomplete evidence, review errors, and actions confidently judged dangerous cannot be overridden. Non-interactive runs have no human approval channel. Ambiguity and low-confidence decisions continue to block, preserving fail-closed autonomous behavior. The reviewer judges an action by its effect, not by the technique it uses or by whether a hostname appears in target scope. A read-only injection probe (a boolean, `UNION SELECT`, or time-based payload), a reflected-input test, or recon passes; a payload that writes or destroys (`DROP`, `DELETE`, `INSERT`, `INTO OUTFILE`, stacked statements, command execution), a mutating request, or any persistent change is blocked or, in the TUI, deferred when its effect is genuinely ambiguous. Scope still controls what Strix actively tests, but the safety reviewer is not a scope enforcement layer. Ordinary passive requests to research services such as `crt.sh`, DNS and WHOIS, package registries, search, and public documentation are allowed when they support an authorized target. Those services do not become targets for scanning or exploitation. ## Deterministic Rules Some outcomes never reach the model. Destructive commands, environment overrides that change which code an interpreter loads (`PYTHONPATH`, `LD_PRELOAD`, `AGENT_BROWSER_SESSION`, and similar), and blocked browser actions are refused outright. A small set of read-only commands is allowed outright, but only when its options are also read-only: `rg --pre` and anything else that hands the command another program to run goes to review instead. Browser observation commands are allowed outright only in the form that just reads: `tab` lists tabs, but `tab new ` navigates and `tab close` discards page state, so a grouped verb with a subcommand goes to review. Commands that wrap another program (`sudo`, `timeout`, `xargs`, `nohup`, and similar) and interactive `write_stdin` payloads cannot be resolved to a single effective action before dispatch, so they are blocked. Issue the command as its own `exec_command` call. ## Scripts When a command executes a script, Strix reads the current entrypoint and local Python imports without importing or running them. Inline `python -c` source is analyzed the same way. Absolute imports resolve against the entrypoint's directory and relative imports against the importing module's package, and an imported name is followed as a submodule as well as an attribute, so the whole local closure is inspected. Decisions bind to content hashes. Dynamic code execution, import-path mutation, unresolved generated commands, oversized dependency closures, entrypoints outside `/workspace`, and unsupported evidence block the action. A command that runs code Strix cannot resolve to an inspectable script — an unrecognized interpreter, or an interpreter given no script — is blocked rather than reviewed against an empty evidence packet. When a command reads a workspace data file — through input redirection (`while read … done < hosts.txt`) or a target-list flag (`ffuf -w words.txt`, `httpx -l hosts.txt`) — that file's contents are attached to the packet so the reviewer can assess the exact entries, queried hosts, or fuzz inputs instead of blocking because it cannot see them. Only workspace-resident files are read; an oversize file is attached truncated. Any workspace change while the action is under review or awaiting approval invalidates the decision. Browser automation inside scripts is blocked in safety modes. Issue browser operations as individual raw `agent-browser` commands so each action can be reviewed against the current snapshot and element references. Commands that create and execute code in one shell expression should be split into separate creation and execution calls. ## Browser Commands Strix continues to use the raw `agent-browser` CLI. In safety modes it assigns an isolated browser session per agent and rejects model-supplied session, profile, or CDP overrides. Interactions with element references require a prior recorded snapshot. A snapshot taken before a navigation or any other page-changing action is stale: the action is blocked and the agent must snapshot again. Composite operations such as `auth login`, arbitrary `eval`, browser state persistence, and uploads are blocked. Guarded login should use explicit fill and submit steps with credentials supplied in the initial user instruction. ## Workspace Isolation By default, user-owned local directories are copied into: ```text strix_runs//.state/workspaces/ ``` The copy is mounted writable, while the original source remains unchanged. `.git`, `.agents`, and `.codex` inside the copy stay read-only: they carry repository and agent-instruction state that survives `--resume`. Copies are retained for resume. Repository targets are already cloned into a disposable location and do not need another copy. In-tree symlinks are materialized. Dangling, cyclic, device, and out-of-tree symlinks are omitted. Files are copied rather than hard-linked. ## Limitations Contextual review reduces accidental harmful actions; it is not a complete network containment boundary. Arbitrary dynamic programs, raw sockets, or processes that ignore proxy settings cannot always be predicted statically. Unresolvable behavior blocks in safety modes. Deterministic rules cover the cases listed above. Every other command is judged by the safety model against compiled evidence, so a tool whose effects are not statically recognizable — a scanner or exploit framework that mutates the target through its own protocol, for example — rests on that judgment rather than on a rule. Strong containment additionally requires externally enforced egress policy and reduced sandbox privileges.