Skip to content
# antigravity full-auto@1.1
Full auto: nothing is asked, nothing is sandboxed, and the three capability keys whose names this build carries in its own settings registry are on. toolPermission is always-proceed -- the product's own words for it are "always-proceed…
[Catalog](/en/ai/catalog)
[Publisher](/en/ai/publishers/account_01KZET6ZKJN7S72T5H4WDV62T0)
- stable_id: setup_01M18ZQADXG465TW3WFDTV7PWK
- version: 1.1
- digest: sha256:e2ac993bcd05d1e085fa1d5c08bf58bff5fc2c62de2030829f5c9761fa78e494
- harness: antigravity
- Purpose: Full auto: nothing is asked, nothing is sandboxed, and the three capability keys whose names this build carries in its own settings registry are on. `toolPermission` is always-proceed -- the product's own words for it are "always-proceed auto-approve tool confirmation", against "accept-edits auto-approve file write" for the weaker one -- and the terminal sandbox is off. Beyond that: the agent may reach files outside the workspace, may see files git is ignoring, and continues instead of stopping when it reaches its generator-invocation ceiling. Those three were off, and switching the approvals off did not switch them on. Their names come from the pinned 1.1.22 artifact's own key registry, and the first is confirmed twice more -- the runtime prints `populatePermissionConfig(...): toolPermission=%v autoExecPolicy=%v enableTerminalSandbox=%t allowNonWorkspaceAccess=%t`, which is four inputs to one decision, and there is a persistence error string for it. `terminalAutoExecutionPolicy` is the fourth input and is deliberately not written: the key is named by the same registry, and the artifact carries AUTO_EXECUTION_POLICY_UNSPECIFIED, _NOT_ENFORCED, _PROCEED_IN_SANDBOX and _REQUIRE_REVIEW, but which spelling the settings file takes cannot be measured here -- and that is now a measurement rather than a shrug. Asked 2026-08-29 with a control: two temporary homes, one holding only `toolPermission` and one holding `toolPermission` beside an invented `nddevInventedControlKey` and a candidate policy value. `plugin list` -- the one credential-free subcommand that starts, reads the settings and exits -- printed the same line and exited 0 for both, and left both files byte-identical to how they were written. **The product accepts a key no product could read, silently.** So no local probe can distinguish a key it reads from one it ignores, and "the value survived" would say nothing: the control is not rejected, so nothing in the run discriminates. The only remaining instrument needs a signed-in session. The three keys above are written because the runtime *prints* them as inputs to one decision; this one is not, because a plausible value the product does not read is worse than an absent one -- it reads as configured and does nothing. A plausible value the product does not read is worse than an absent one; it reads as configured and does nothing. `sandboxAllowNetwork`, `sandboxAllowedDomains`, `terminalAllowedCommands` and `terminalDeniedCommands` are named by the registry too and all govern a sandbox this posture switches off. This product documents a global instruction file after all -- a consolidated `AGENTS.md` under `rules/`, which its own reference recommends over separate rule files. That sentence read the other way here until 2026-08-29, taken from the pages that had been read rather than from the reference inside the artifact this baseline pins. This is a setup posture -- keys in this product's own configuration file. It is not an execution profile and it grants no environment: what it changes is what the product asks you and which of its own tools exist, not what anyone is permitted to run. The key measurement behind this posture: the settings-key registry and the permission log line in the pinned 1.1.22 artifact, whose bytes match this baseline's own sha256.
- Target role:
- posture: full-auto
- trust_lane: authoritative
- author_verified: Yes
- component_verified: Yes
- Lifecycle: active
- Author: account_01KZET6ZKJN7S72T5H4WDV62T0
- Tags: code-review, devops, planning
- install: ai-stp registry version --kind setup --id setup_01M18ZQADXG465TW3WFDTV7PWK --version 1.1
```
ai-stp registry version --kind setup --id setup_01M18ZQADXG465TW3WFDTV7PWK --version 1.1
```
ai_stp