Tool Comparison Matrix — Agent Security: Guardrails¶
tool-comparison-matrix-ai-agent.md からの分離ドキュメント。 エージェントの権限設定・ツール許可ルール・Configuration Examples を詳述する。
History¶
| 日付 | 内容 |
|---|---|
| 2026-06-27 | Codex (OpenAI) を追加 |
| 2026-06-16 | 本体から分離して新規作成。Cursor IDE/CLI 権限設定を追加 |
Guardrails Configuration¶
| 設定項目 | Antigravity | Claude Code | Codex | Cursor | GitHub Copilot | Kiro |
|---|---|---|---|---|---|---|
| ドキュメント | antigravity.google | docs.anthropic.com | developers.openai.com/codex | IDE / CLI | docs.github.com | kiro.dev |
| 権限設定ファイル | .gemini/antigravity-cli/settings.json |
.claude/settings.json |
.codex/config.toml (approval_mode) |
IDE: .cursor/permissions.json / CLI: .cursor/cli.json |
.github/copilot/settings.json |
.kiro/agents/*.json |
| ユーザー権限設定 | ~/.gemini/antigravity-cli/settings.json |
~/.claude/settings.json |
~/.codex/config.toml |
~/.cursor/cli-config.json (CLI) / IDE は動的承認 |
~/.copilot/permissions-config.json |
~/.kiro/agents/*.json |
| ローカル設定 (Git 除外) | - | .claude/settings.local.json |
- | - | .github/copilot/settings.local.json |
- |
| ツール許可ルール | sandbox 設定 | allow / deny リスト |
sandbox modes (read-only / workspace-write / danger-full-access) + approval mode (suggest / auto-edit / full-auto) | mcpAllowlist / terminalAllowlist / autoRun |
permissions-config.json (自動記録) |
allowedTools / toolsSettings |
| 管理者設定 (Enterprise) | GCP Organization policy | managed policy (JSON) | requirements.toml (管理者ポリシー) |
- | Organization policy | - |
Configuration Examples¶
Kiro (.kiro/agents/default.json):
{
"allowedTools": ["read", "write", "shell"],
"toolsSettings": {
"shell": {
"allowedCommands": ["npm test.*"],
"deniedCommands": ["rm -rf.*", "git push --force.*"]
}
}
}
Claude Code (.claude/settings.json):
{
"permissions": {
"allow": ["Read", "Write", "Bash(npm test *)", "Bash(go test *)"],
"deny": ["Bash(rm -rf *)", "Bash(git push --force *)", "Bash(terraform apply *)"]
}
}
Codex (.codex/config.toml):
# .codex/config.toml
sandbox = "workspace-write"
approval_mode = "auto-edit"
[features]
hooks = true
Cursor IDE (.cursor/permissions.json):
{
"mcpAllowlist": ["github:*"],
"terminalAllowlist": ["git", "npm test", "go test"],
"autoRun": {
"block_instructions": ["Destructive git operations: push --force, reset --hard, clean -f.", "Any command that installs packages or modifies .env files."]
}
}
Cursor CLI (.cursor/cli.json):
{
"version": 1,
"editor": { "vimMode": false },
"permissions": {
"allow": ["Shell(git)", "Shell(go test)", "Read(src/**)", "Write(src/**)"],
"deny": ["Shell(rm -rf)", "Shell(sudo)", "Read(.env*)", "Write(~/**)"]
}
}
GitHub Copilot (.github/copilot/settings.json):
{
"hooks": {
"pre-tool-use": [{ "event": "Bash", "command": "echo 'confirm'" }]
}
}
Guidelines¶
→ エージェント導入時は以下のセキュリティ設定を必ず行う:
- 本番操作は明示承認必須とする (破壊的操作の制限を指示ファイルに明記)
.env/ credentials / secrets へのアクセス制限を定義する- 外部へのコード・データ送信ルールを明記する
- Instructions / Rules は Git 管理し、PR レビュー対象とする
- 学習利用・データ保持ポリシーを確認し、機密コードが学習に使われないプランを選択する