Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

APX does not translate a mistyped agent autonomy value such as permissive into permiso. If the invalid value is stored in an agent file, APX drops it and the agent inherits the project’s autonomy setting; if the value is entered directly through the CLI, APX rejects it and lists the accepted choices. That avoids a fuzzy permission guess—but inheritance may be broader than the restriction you intended.

Why a typo should not choose an agent’s permissions

An autonomy value determines what an agent can do without asking. Guessing that an unknown word is close to a particular mode would turn a spelling error into a permission decision. APX instead treats an invalid stored declaration as absent, letting the agent inherit the project baseline, and treats invalid direct CLI input as an error that the user can correct.

This is a deliberate distinction between two failure paths, not a guarantee that inheritance is always restrictive. If the project baseline grants more autonomy than you intended for that agent, dropping its malformed override will not preserve the narrower intent.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

APC carries project context; APX enforces local permissions

Agent Project Context (APC) carries portable project context, including agent files, roles, skills, and metadata. APX is the local runtime that reads that context and enforces tool permissions on the machine. A portable declaration can request an autonomy mode, but APX makes the effective local permission decision. The source article describing this behavior does not establish that these runtime details were independently verified against APX source code.

What the three autonomy modes mean

The described APX modes are total, automatico, and permiso. Their practical distinctions are summarized below.

Mode Described behavior
total Runs tools without confirmation.
automatico Allows safe work, while some destructive, outbound, runtime, MCP, and filesystem-mutating work can require confirmation.
permiso Runs only tools listed in allowed_tools directly; asks before using other tools.

These descriptions distinguish the modes at a high level; they are not a complete inventory of every tool or action covered by each permission check.

How agent overrides and inheritance work

An agent-level Autonomy: declaration overrides the project baseline for that agent’s turn. If the declaration is absent, the agent inherits the project setting. Inheritance is therefore an actual configuration state, not a synonym for a particular mode.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the CLI option, the described behavior is:

Input Result
No --autonomy flag Keeps the current agent setting; omission does not reset it.
--autonomy inherit Clears the agent override so it follows the project mode.
--autonomy automatico, permiso, or total Sets an explicit agent override.
Invalid value in stored agent metadata Drops the value; the agent inherits the project baseline.
Invalid value entered directly through the CLI Rejects the input and reports accepted values, including inherit.

Why stored metadata and CLI input fail differently

Stored metadata falls back to the project setting

When APX encounters an unrecognized value in stored agent metadata, the described behavior is to drop that value rather than map it to a nearby mode. The agent then inherits the project baseline. This avoids silently turning a typo into a guessed permission level.

But fallback is not the same as preserving the agent’s intended restriction. If the project setting is broader than the intended agent setting, a typo such as permissive can leave the agent using that broader baseline instead of permiso.

Direct CLI input is rejected for correction

For direct input, APX can show the error immediately and provide a correction path. The source article states: “That is why APX handles direct CLI input differently: apx agent ... --autonomy rejects an invalid value and tells the user the accepted modes, including inherit.” Use the recognized spelling exactly rather than relying on an inferred match.

How to check an agent’s effective autonomy

If a specific agent must pause for tools outside its allowed list, check both its declaration and the project baseline. Then test an action that should require confirmation; a pause is a practical check that the intended restriction is taking effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Inspect the agent file’s Autonomy: declaration and confirm that the value is exactly total, automatico, or permiso, as intended.
  2. Check the project autonomy setting. If the agent declaration is absent or invalid, that project setting is inherited.
  3. For CLI changes, use one of the recognized modes or inherit. If you omit --autonomy, do not assume the current agent setting is cleared.
  4. Try a tool action that should require confirmation under the selected mode. If it runs directly, review the agent declaration and baseline before relying on that configuration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is established—and what is not

The behavior described here comes from a DEV Community article credited to Manuel Bruña for Agent Project Context. Its publication date is shown as Sep 30, but the year is unspecified. The article says that a valid agent override is applied to the active-turn configuration before the permission guard and risk handling; that implementation detail is an attributed description, not independently confirmed source-code behavior.

No incident rates or measured security outcomes are established for this validation behavior. The practical rationale is narrower: rejecting direct invalid input and dropping invalid stored metadata avoid a fuzzy mapping, while the inheritance fallback can still produce a broader effective setting than the agent author intended.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.