The No That Made GHL Command Safer
Last week I posted a poll here. I was excited about it. GHL Command was about to get the ability to create and delete client sub-accounts for you.
Riyaz R replied with something better than a yes.
He said he keeps two things manual no matter what: user access and sub-account management. His reason: in case of prompt injection, or the agent going rogue. And he asked that if we ship it, we make it optional so he could turn it off.
That is not resistance. That is free security architecture. So instead of shipping the exciting default, we treated his threat model as the design requirement, then generalized it: any tool could be a liability in somebody's threat model. So every tool got an off switch.
How we built it:
• Wrote the design plan first, then had an independent adversarial AI attack the plan. It found 18 issues, including a critical one: five tools registered through a side path the off switch would have silently missed.
• Built it, then ran a second adversarial audit on the code. Two more findings. Fixed both.
• Proved it on the real shipped binary: 5 live proofs, 736 tests.
What shipped in v3.56.0, live now:
• Sub-account create and delete is OFF by default. You opt in with GHL_ENABLE_ACCOUNT_ADMIN=1, and the setup wizard asks first (default is No).
• A universal off switch: GHL_DISABLED_TOOLS and GHL_DISABLED_MODULES can disable any tool or any module. A disabled tool never registers. The AI cannot call it or even see it, so prompt injection has nothing to grab.
• There is deliberately no way to re-enable a tool from inside a conversation. Turning something back on takes a config edit and a full restart. In other words, a human.
• You cannot brick yourself: 4 recovery tools ignore denial, with a warning.
• health_check now shows your gating state and catches typos, so a misspelled tool name warns loudly instead of silently failing open.
The lesson: excitement ships features. Caution ships trust. AI tools with write access to your business need human-owned kill switches, and they should exist before the incident, not after.
Thank you, Riyaz. This one is yours.
To get it: quit Claude fully and reopen (it auto-updates), or run npm install -g @elitedcs/ghl-mcp@latest. The full walkthrough is in the README under "Turning tools off (security)", and I attached the Security Controls Admin Guide to this post.
1
1 comment
Jerry Relth
3
The No That Made GHL Command Safer
powered by
GHL Command
skool.com/ghl-command-5986
The AI operator's room for GoHighLevel agencies.
Build your own community
Bring people together around your passion and get paid.
Powered by