Review agent · Platform & AI

Privilege & file permissions

Checks file permissions, temp files, symlinks and unnecessary root.

scripts/setup.sh1tmp=/tmp/build.$$2cp app.conf "$tmp"3chmod 777 "$tmp"4sudo ./install.shPrivwhat this review answersWorld-writable files?Predictable temp files or symlinks?Running as root needlessly?$ verdict REAL ISSUE$ fix least permissions, mkstemp▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

World-writable files, predictable temp paths and needless root are classic ways a small foothold becomes full control of a host.

These bugs are subtle — a race on a temp file looks like ordinary code. The agent knows the safe patterns and points to them.

What it checks

  • World-writable or overly broad permissions (chmod 777)
  • setuid / setgid usage
  • Insecure temp-file creation and unsafe symlink following
  • Code that runs as root unnecessarily

When it marks a finding as a likely false positive

  • Permissions match the file's purpose
  • Temp files are created atomically

The fix it suggests

  • Least permissions
  • Atomic temp files (mkstemp)
  • Symlink-safe operations and dropping privileges

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does it apply to Windows code?

Its checks are Unix-centred (permissions, setuid, symlinks). Findings that don't fit any specialist go to the general reviewer.

Related agents

  • AI / LLM safety — Checks LLM application code for prompt injection and unsafe handling of model output.
  • Network & transport security — Checks that data in transit is encrypted and certificates are actually verified.
  • Mobile client security — Reviews Android and iOS code for on-device storage, transport and component exposure.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Privilege & file permissions agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free