Mistral Vibe Tightens Permissions for Background Processes and Forks

Mistral VibeView original changelog

Mistral Vibe 2.26.0 closed several permission and trust gaps: background starts now respect the shell allowlist and denylist, tools set to permission = "never" now deny sensitive paths, and isolated forks no longer inherit or revoke the caller's --trust grant. The release also made the ~/.vibe/.env API key fallback owner-only (0600).

Key Takeaways

  • Background process starts now honor the shell allowlist and denylist and ask before running.
  • Tools set to permission = "never" now deny sensitive paths instead of prompting for them.
  • Isolated forks no longer inherit or revoke the caller's --trust grant.
  • The ~/.vibe/.env key fallback is now owner-only (0600), protecting saved keys from other local accounts.
  • Plugins cannot claim the reserved subagent or skill namespaces.
  • Together the fixes target one question: can the agent act outside what the user authorized.

A pattern of boundary fixes

Version 2.26.0 of Mistral Vibe contains a cluster of changes that all answer the same question: can the agent act outside what the user authorized? Several of them tighten or repair that boundary.

Background processes follow the shell rules

A background start now asks before running, honors the shell's allowlist and denylist, and remembers the approval for later starts. A start that sets its own environment or working directory always asks. Writing to a background process asks for that process only in the current session.

permission = "never" now denies sensitive paths

On the unified backend, a tool set to permission = "never" now denies a sensitive path instead of prompting for it. Previously, such a path could surface as an approval prompt that a user might accept by habit. A related fix restores correct behavior for a file tool set to never with an allowlist: it now writes where the allowlist permits instead of refusing everything.

Forks keep their own trust

Isolated forks no longer inherit or revoke the caller's --trust grant, so a fork cannot quietly widen or remove the trust the parent session was given. Forked sessions in managed worktrees also now use independent managed worktrees, and managed-worktree forks warn when uncommitted source changes remain outside the fork.

Hooks and plugins

Plugins can no longer claim the reserved subagent or skill namespaces, which prevents a plugin from impersonating built-in surfaces.

API key file permissions

The ~/.vibe/.env fallback used when the OS keyring is unavailable is now created owner-only (0600), so a saved key is no longer readable by other accounts on the same machine.

Mistral Vibe Fixes Background, Fork and Path Permissions | Yet Another Changelog