> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Trust and permissions

> Control filesystem, process, network, and integration authority

TurenOS evaluates tool requests against ordered permission rules. A request is allowed, denied, or paused for interactive approval.

## Safe approval practice

* Prefer one-time approval for unfamiliar commands.
* Scope filesystem rules to one project or explicit external directory.
* Inspect commands containing recursive deletion, history rewriting, publishing, privilege escalation, or credential access.
* Review the target URL and data sent by web or MCP tools.
* Do not treat a model's explanation as proof that a command is safe.

## Dangerous commands

The shell layer detects common destructive operations and wrapper variants. This reduces accidental broad deletion but cannot prove arbitrary shell programs safe.

## Remote services

Remote provider and MCP connections are qualified by URL, transport, and configured trust. Hosted OAuth controls identity; TurenOS permissions separately control whether agents can invoke discovered tools.

## Analysis and execution

Static binary/document/email/packet analyzers do not execute selected targets. Explicit execution features, including authorized HTTP security testing and controlled Rosetta execution, use separate narrow tools and scopes.

<Warning>
  Approved tools run with your account's operating-system authority. Use a disposable environment when the repository or artifact itself is hostile.
</Warning>
