# Use --allowedTools to whitelist specific agent capabilities
Restrict agent tool access to a safe subset
Most CLI agents support tool allowlisting. Limiting tools prevents the agent from taking unexpected actions — for example, allowing Read but not Write during exploration, or allowing Bash but not network access. Defense-in-depth for autonomous agents.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.