Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(tools): resource/DoS hardening across file, web, runtime, sandbox

4 months ago

055a0cf
Authored
mweinbach6/9/2026, 6:42:37 PM
- read: stat() images before reading them into memory so a workspace-planted
  multi-GB "image" cannot OOM the process before the size check.
- edit: cap oldString/newString (2 MB) and reject files >10 MB by stat().
- webFetch: cap the inline response body on the decoded stream (decompression-
  bomb guard); bound the download filename-suffix loop; honor a no-network
  sandbox policy; frame fetched content as untrusted (carried from P2).
- webSearch: honor a no-network sandbox policy.
- exa/parallel: add a 30s per-request timeout so a hung endpoint can't stall
  the turn.
- antigravity runtime: validate model-supplied tool args against the Zod schema
  before execute() (mirrors the pi runtime) so malformed Gemini calls can't
  bypass read/write/edit bounds.
- bwrap: add --unshare-ipc (covert-channel hardening) + probe.
- bash redactSecrets: cover UPPER_CASE *_API_KEY/TOKEN/SECRET assignments and
  gh*/github_pat/npm/slack/AWS token formats.
- todoWrite: remove the dead module-global todo store/listeners (a cross-session
  footgun in the server); todos route per-session via ctx.updateTodos.

Adds regression tests for the edit cap, webFetch inline cap + network guard,
and --unshare-ipc.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parentd9a59c0

26 files changed
  • src/platform/sandbox/bwrap.ts+5−2
  • src/platform/sandbox/detect.ts+1−0
  • src/runtime/antigravityRuntime.ts+15−2
  • src/tools/bash.ts+11−1
  • src/tools/edit.ts+14−2
  • src/tools/exa.ts+10−1
  • src/tools/parallel.ts+9−1
  • src/tools/read.ts+8−0
src/tools/todoWrite.ts
+5
−26
  • src/tools/webFetch.ts+49−3
  • src/tools/webSearch.ts+9−0
  • test/platform/sandbox.test.ts+2−0
  • test/tools/tools.ask.test.ts+0−2
  • test/tools/tools.bash.test.ts+0−2
  • test/tools/tools.createTools.test.ts+0−2
  • test/tools/tools.edit.test.ts+12−2
  • test/tools/tools.glob.test.ts+0−2
  • test/tools/tools.grep.test.ts+0−2
  • test/tools/tools.harness.ts+1−3
  • test/tools/tools.memory.test.ts+0−2
  • test/tools/tools.read.test.ts+0−2
  • test/tools/tools.skill.test.ts+0−2
  • test/tools/tools.todoWrite.test.ts+0−2
  • test/tools/tools.webFetch.test.ts+50−4
  • test/tools/tools.webSearch.test.ts+0−2
  • test/tools/tools.write.test.ts+0−2