Files
Niv Hertz 2c04821abe feat: add global config guards for risky, costly, and read-only commands (#77)
## Summary
- Add three new global config fields to `~/.cx/config.toml`:
`allow_risky_commands`, `allow_costly_commands`, and `read_only`
- `allow_risky_commands` (default: true) — when false, blocks write
operations under `iam` and `archive` commands while still allowing reads
- `allow_costly_commands` (default: true) — when false, blocks `olly
ask` (AI assistant queries)
- `read_only` (default: false) — when true, blocks ALL write operations
globally (persistent equivalent of `--read-only` flag)
- Command categories defined via `is_risky()`/`is_costly()` methods on
the `Commands` enum — tags live with the command definition, not in
hardcoded arrays
- First profile creation (`cx profiles add`) prompts for risky/costly
settings
- 10 integration tests covering all gating scenarios

## Test plan
- [x] `cargo fmt` — clean
- [x] `cargo clippy` — no warnings
- [x] `cargo test` — all tests pass (including 10 new integration tests)
- [ ] Manual: verify first-profile prompt flow with `HOME=/tmp/test-cx
cx profiles add`
- [ ] Manual: verify blocked commands show clear error messages pointing
to config.toml

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-05-05 21:20:29 +03:00
..