What Is Permissive Mode in OpenClaude Safety Settings?

OpenClaude's permissive mode relaxes application-level safety heuristics and bypasses legacy Bash command-injection checks while retaining critical filesystem guards, allowing faster automated workflows with fewer false positives.

OpenClaude, the open-source CLI tool maintained at Gitlawb/openclaude, implements a configurable safety system to protect users from accidental command injection and dangerous file operations. The OpenClaude permissive mode setting offers a middle ground between maximum security and development velocity, controlled via the OPENCLAUDE_SAFETY_LEVEL environment variable. Understanding when and how to deploy this mode requires examining the specific heuristics that change and those that remain enforced.

How OpenClaude Permissive Mode Works

The safety architecture centers on the OPENCLAUDE_SAFETY_LEVEL environment variable defined in src/utils/permissions/safetyLevel.ts. By default, the system operates in strict mode, applying comprehensive validation to every operation. When you set the variable to permissive, the application immediately relaxes specific validation layers while maintaining core protective barriers.

Environment Variable Configuration

To activate permissive mode, export the environment variable before launching the CLI or programmatically within your Node.js process. According to the source code in safetyLevel.ts (lines 14-16), the isPermissiveSafetyLevel() function returns true only when the environment variable exactly matches the string 'permissive'.

// Enable via environment variable
process.env.OPENCLAUDE_SAFETY_LEVEL = 'permissive';

// Verify current mode programmatically
import { isPermissiveSafetyLevel } from './src/utils/permissions/safetyLevel';

if (isPermissiveSafetyLevel()) {
  console.log('Running with relaxed safety heuristics');
}

Documentation in docs/advanced-setup.md (lines 652-655) describes this user-facing configuration and provides export statements for shell environments.

Relaxed Application-Level Heuristics

When active, OpenClaude permissive mode modifies several validation paths to reduce friction during development:

  • Bash command-injection validation: The legacy security path in src/tools/BashTool/bashSecurity.ts (lines 2596-2774) is completely bypassed. This allows benign command substitutions—such as echo $(date)—that would be flagged and blocked under strict mode.

  • Sensitive file prompts: Routine confirmation prompts for files on the broad sensitive-file list—including package.json, requirements.txt, and similar configuration files—are automatically skipped. This accelerates workflows involving frequent edits to these files.

  • Interpreter allow-rules: Ordinary interpreter patterns like Bash(python:*) and Bash(npm run:*) remain active when the engine runs in auto mode, ensuring common development commands execute without interruption.

Critical Safety Guarantees That Remain

Despite the relaxed heuristics, permissive mode does not constitute a "dangerous mode." The following protections remain fully enforced according to the implementation in src/utils/permissions/filesystem.ts (lines 835-836):

  • Dangerous directory checks: Operations targeting system-critical paths remain blocked.
  • Windows path validation: Malformed or dangerous Windows-specific paths are rejected.
  • Symlink resolution: Symbolic links are resolved and validated to prevent directory traversal attacks.
  • UNC path protection: Universal Naming Convention paths undergo strict validation.

Additionally, the model-level system prompt remains unchanged. The LLM continues to receive the same safety-focused instructions regardless of the application-level safety setting, ensuring the underlying language model maintains its safety training and behavioral constraints.

Third-Party Provider Considerations

A documented side effect occurs when combining permissive mode with third-party AI providers. Under strict mode, an AI classifier double-checks potentially unsafe commands before execution. In permissive mode, this classifier is skipped entirely, which the CLI notes with a startup warning as documented in CHANGELOG.md (line 623).

Teams using non-Anthropic providers should weigh this reduced oversight against their workflow requirements, as the application relies solely on the remaining filesystem guards without the secondary model-based safety check.

Summary

  • OpenClaude permissive mode is enabled by setting OPENCLAUDE_SAFETY_LEVEL=permissive before launching the application.
  • The mode bypasses legacy Bash command-injection validation (lines 2596-2774 in bashSecurity.ts) and skips prompts for sensitive files like package.json and requirements.txt.
  • Critical guards—including dangerous directory checks, Windows path validation, symlink resolution, and UNC path protection—remain active per filesystem.ts (lines 835-836).
  • The system prompt sent to the LLM does not change; only application-level heuristics are relaxed.
  • Third-party providers skip the AI classifier safety check when running in permissive mode, triggering a CLI warning on startup.

Frequently Asked Questions

How do I enable permissive mode in OpenClaude?

Export the OPENCLAUDE_SAFETY_LEVEL environment variable set to permissive in your shell configuration, .env file, or directly before running the CLI. The isPermissiveSafetyLevel() function in src/utils/permissions/safetyLevel.ts parses this value at runtime to determine the active safety profile.

What is the difference between strict and permissive mode in OpenClaude?

Strict mode applies full Bash command-injection validation and prompts for every sensitive file modification. Permissive mode bypasses the legacy Bash security path in bashSecurity.ts and skips routine prompts for files like requirements.txt, while keeping critical filesystem guards intact and maintaining the same LLM system prompt.

Is permissive mode safe for production use?

Permissive mode retains dangerous-directory checks, Windows path validation, symlink resolution, and UNC path protection defined in src/utils/permissions/filesystem.ts. However, it disables the AI classifier for third-party providers and removes application-level heuristics, making it suitable only for trusted development environments where false positives impede productivity.

Does permissive mode change the LLM system prompt?

No. Permissive mode affects only application-level safety heuristics implemented in the TypeScript source code. The model-level system prompt remains identical, meaning the underlying language model maintains its standard safety instructions and behavior constraints regardless of the OPENCLAUDE_SAFETY_LEVEL setting.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →