Skip to content

[Security][P1] Gate auto-approve by environment mode #15

@EXboys

Description

@EXboys

Goal

收敛 SKILLBOX_AUTO_APPROVE 风险:仅在开发模式允许,生产模式默认拒绝并可审计。

Task checklist

  • 增加运行模式:SKILLLITE_ENV=dev|prod(默认 prod)
  • prod 下忽略或拒绝 SKILLBOX_AUTO_APPROVE
  • 非交互自动确认路径增加严格校验与审计
  • 提供显式 override(仅 CLI flag,带强警告)
  • 增补测试:dev/prod 分支覆盖

Acceptance criteria

  • 生产模式下无法静默 auto-approve
  • 所有确认绕过路径有审计记录
  • 文档清楚说明行为差异

Dependencies

  • Issue 2

Estimate

1–1.5 天

Metadata

Metadata

Assignees

No one assigned

    Labels

    hardeningSecurity hardeningphase-securitySecurity phase planningsecuritySecurity related work

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions