How to Configure OpenClaude Safety Strictness: Environment Variables and Code Implementation
Set the OPENCLAUDE_SAFETY_LEVEL environment variable to permissive, balanced, or strict to control OpenClaude's application-level safety heuristics without rebuilding the CLI.
OpenClaude, an open-source CLI tool in the Gitlawb/openclaude repository, provides configurable safety guardrails to prevent unsafe model responses and accidental file modifications. Understanding how to configure OpenClaude safety strictness allows you to balance security against productivity, reducing false-positive interruptions during development workflows.
Understanding the Three Safety Levels
The safety subsystem defined in src/utils/permissions/safetyLevel.ts exports a SafetyLevel type supporting three distinct modes:
- strict (default): All built-in safety checks are active, prompting for any potentially dangerous operation such as editing
.gitfiles or detecting command-injection patterns. - balanced: Functionally identical to
strict, maintained for backward compatibility. - permissive: Relaxes heuristics that generate false-positive refusals while preserving model-level safety checks, allowing operations like editing
.gitmodulesor running scripts containing$(date)without additional prompts.
According to the source code in src/utils/permissions/safetyLevel.ts, the system reads process.env.OPENCLAUDE_SAFETY_LEVEL and defaults to balanced when the variable is unset or contains an unknown value.
Setting the OPENCLAUDE_SAFETY_LEVEL Environment Variable
Temporary Configuration for a Single Session
Apply the setting for your current shell session only:
export OPENCLAUDE_SAFETY_LEVEL=permissive
openclaude run myscript.js
Permanent Configuration in Shell Profiles
Add the export to your shell configuration file to persist the setting across sessions:
echo 'export OPENCLAUDE_SAFETY_LEVEL=permissive' >> ~/.bashrc
source ~/.bashrc
For Zsh users, substitute ~/.bashrc with ~/.zshrc.
How Safety Checks Are Applied in the Codebase
The safety level influences operational logic across multiple permission modules. In src/utils/permissions/filesystem.ts, the system checks isPermissiveSafety() to determine whether to apply strict guardrails before editing sensitive files. Similarly, src/utils/permissions/permissionSetup.ts respects the permissive flag to bypass certain classifier checks during permission graph initialization.
When OPENCLAUDE_SAFETY_LEVEL is set to permissive, these components reduce their heuristic sensitivity, specifically relaxing bash-injection detection and filesystem safeguards while maintaining core model refusal protections.
Programmatically Detecting the Safety Level
For plugin developers or custom tool builders, the isPermissiveSafety() function provides runtime detection capabilities:
import { isPermissiveSafety } from './utils/permissions/safetyLevel.js';
if (isPermissiveSafety()) {
console.log('Running with relaxed safety heuristics.');
} else {
console.log('Full safety checks are enforced.');
}
This utility allows conditional logic based on the current safety configuration without directly accessing environment variables.
Summary
- Set
OPENCLAUDE_SAFETY_LEVELtostrict,balanced, orpermissiveto control safety heuristics in Gitlawb/openclaude - The default behavior equals
strict(orbalanced, which is functionally identical) permissivemode reduces false positives for benign operations while keeping model-level protections- Implementation resides in
src/utils/permissions/safetyLevel.tsand affectsfilesystem.tsandpermissionSetup.ts - Use
isPermissiveSafety()to check levels programmatically in extensions
Frequently Asked Questions
What is the default safety level if I don't set the environment variable?
If OPENCLAUDE_SAFETY_LEVEL is missing or contains an unrecognized value, OpenClaude defaults to balanced, which is functionally identical to strict. This ensures maximum protection for users who haven't explicitly configured the setting.
Does permissive mode disable all safety protections?
No. According to the source code in src/utils/permissions/safetyLevel.ts, permissive only relaxes application-level heuristics that cause false positives, such as aggressive bash-injection pattern matching or strict filesystem guards. Model-level refusal prompts and core safety checks remain active to prevent genuinely dangerous operations.
Can I change the safety level without restarting OpenClaude?
Yes. Since the code reads process.env.OPENCLAUDE_SAFETY_LEVEL at runtime, you can export the variable in your current shell session before running openclaude. However, already-running OpenClaude processes will not pick up changes until restarted.
Where is the safety level configuration documented officially?
The official documentation for configuring OPENCLAUDE_SAFETY_LEVEL resides in docs/advanced-setup.md within the Gitlawb/openclaude repository, providing additional context and examples beyond the source code implementation.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →