Dashboard › opencode › Permission save resources
01a07f25-91b7-77d3-a2b0-1ef92f551bffTrap: passing an arbitrary command resource through PermissionAssertInput.save looks convenient because approval can be reused, but it persists model-controlled command grants beyond the current invocation. Fix: authorize the canonical shell resource immediately before the side effect and never place arbitrary command resources in save.