Mistral Vibe Tightens Permissions for Background Processes and Forks
Mistral Vibe 2.26.0 closed several permission and trust gaps: background starts now respect the shell allowlist and denylist, tools set to permission = "never" now deny sensitive paths, and isolated forks no longer inherit or revoke the caller's --trust grant. The release also made the ~/.vibe/.env API key fallback owner-only (0600).
Key Takeaways
- Background process starts now honor the shell allowlist and denylist and ask before running.
- Tools set to
permission = "never"now deny sensitive paths instead of prompting for them. - Isolated forks no longer inherit or revoke the caller's
--trustgrant. - The
~/.vibe/.envkey fallback is now owner-only (0600), protecting saved keys from other local accounts. - Plugins cannot claim the reserved
subagentorskillnamespaces. - Together the fixes target one question: can the agent act outside what the user authorized.
A pattern of boundary fixes
Version 2.26.0 of Mistral Vibe contains a cluster of changes that all answer the same question: can the agent act outside what the user authorized? Several of them tighten or repair that boundary.
Background processes follow the shell rules
A background start now asks before running, honors the shell's allowlist and denylist, and remembers the approval for later starts. A start that sets its own environment or working directory always asks. Writing to a background process asks for that process only in the current session.
permission = "never" now denies sensitive paths
On the unified backend, a tool set to permission = "never" now denies a sensitive path instead of prompting for it. Previously, such a path could surface as an approval prompt that a user might accept by habit. A related fix restores correct behavior for a file tool set to never with an allowlist: it now writes where the allowlist permits instead of refusing everything.
Forks keep their own trust
Isolated forks no longer inherit or revoke the caller's --trust grant, so a fork cannot quietly widen or remove the trust the parent session was given. Forked sessions in managed worktrees also now use independent managed worktrees, and managed-worktree forks warn when uncommitted source changes remain outside the fork.
Hooks and plugins
Plugins can no longer claim the reserved subagent or skill namespaces, which prevents a plugin from impersonating built-in surfaces.
API key file permissions
The ~/.vibe/.env fallback used when the OS keyring is unavailable is now created owner-only (0600), so a saved key is no longer readable by other accounts on the same machine.