Review agent · Platform & AI
Privilege & file permissions
Checks file permissions, temp files, symlinks and unnecessary root.
Illustrative example of how this agent reviews a finding.
Why this agent matters
World-writable files, predictable temp paths and needless root are classic ways a small foothold becomes full control of a host.
These bugs are subtle — a race on a temp file looks like ordinary code. The agent knows the safe patterns and points to them.
What it checks
- World-writable or overly broad permissions (chmod 777)
- setuid / setgid usage
- Insecure temp-file creation and unsafe symlink following
- Code that runs as root unnecessarily
When it marks a finding as a likely false positive
- Permissions match the file's purpose
- Temp files are created atomically
The fix it suggests
- Least permissions
- Atomic temp files (mkstemp)
- Symlink-safe operations and dropping privileges
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Does it apply to Windows code?
Its checks are Unix-centred (permissions, setuid, symlinks). Findings that don't fit any specialist go to the general reviewer.
Related agents
- AI / LLM safety — Checks LLM application code for prompt injection and unsafe handling of model output.
- Network & transport security — Checks that data in transit is encrypted and certificates are actually verified.
- Mobile client security — Reviews Android and iOS code for on-device storage, transport and component exposure.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Privilege & file permissions agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free