{ "name": "default", "version": "1.0.0", "description": "Default policy — allows common development operations with restrictions.", "defaultPermission": "deny", "filesystem": [ { "path": "./**", "operations": ["read", "write", "append"], "permission": "allow" }, { "path": "/tmp/**", "operations": ["read", "write", "append", "delete"], "permission": "allow" }, { "path": "/etc/**", "operations": ["read"], "permission": "allow" } ], "network": [ { "host": "*.npmjs.org", "protocols": ["https"], "permission": "allow" }, { "host": "registry.npmjs.org", "protocols": ["https"], "permission": "allow" }, { "host": "github.com", "protocols": ["https"], "permission": "allow" }, { "host": "api.github.com", "protocols": ["https"], "permission": "allow" } ], "exec": [ { "command": "node", "permission": "allow" }, { "command": "npm", "permission": "allow" }, { "command": "git", "permission": "allow" }, { "command": "tsc", "permission": "allow" } ], "envAllowlist": ["NODE_ENV", "PATH", "HOME", "USER", "SHELL", "TMPDIR", "PWD"], "auditLogPath": "./audit.log" }