posted an update —

The honest limitation until today: four fixed tools meant four diagnosable failure families. Ask about anything else and it correctly said "I cannot see that, and I will not guess" — accurate, but not useful.

run_readonly_command changes that: the agent can now run one read-only command of its own choosing, while the four fixed tools remain for the common cases. The whitelist grew from 32 commands to 87 for normal Ubuntu and RHEL hosts — ps, du, dmesg, journalctl, ss, netstat, ip, lsof, iostat, dpkg, rpm, awk, sed, jq. The blocklist grew to 142 tokens and now includes shells, interpreters and network clients, with new guards for write flags (sed -i, journalctl --vacuum-time, dpkg -i, ip addr add), read-only subcommand allowlists for systemctl and service, and raw-string checks for command substitution, pipes into a shell and file redirection.

Relaxing the surface required tightening the enforcement: the blocklist is now applied only at command positions, because a naive token scan cannot tell /etc/passwd (a file being read) from /bin/rm (a command being run), and the loop-level guardrail now enforces strictness per tool — only propose_remediation may carry a state-changing command.

The same run that proved it found three more bugs: our own density scan used $(...) and no longer passed the policy, the agent was not told which host the CLI had selected, and a turn that hit the output token limit crashed instead of continuing.

Same host, same model, memory-pressure alert, before and after:

Before: "There is no ps/top-style probe in my toolset… I cannot name the leaking process from free -m alone, and I will not guess."

After: ran ps aux --sort=-rss, cat /proc/meminfo, /proc/pressure/memory, the container's cgroup accounting and dmesg | grep -i oom; ruled the container out on cgroup evidence (memory.current 207 MB, oom_kill 0), confirmed host pressure independently (AnonPages 4.7 GB, Committed_AS 49 GB against a 20 GB commit limit), and reported that the consumer sits outside the visible PID namespace — with the exact command to run where it is visible.

Log in or sign up for Devpost to join the conversation.