4 months ago
28b9854The env allowlist (minimalSandboxEnv/SANDBOX_ENV_ALLOWLIST) was unreachable: the sandboxed spawn used `opts.env ?? minimalSandboxEnv()`, but opts.env (ctx.toolEnv) is always a full clone of process.env, so the allowlist never ran. Every sandboxed command therefore received the server's entire env, including ANTHROPIC_API_KEY and other provider secrets. The OS sandbox confines writes but not env reads, and network is allowed by default, so an auto-approved command could exfiltrate keys (curl ...$ANTHROPIC_API_KEY). Filter the sandboxed child env to the allowlist applied to toolEnv. Runtime vars the command needs (COWORK_ARTIFACT_RUNTIME_*, COWORK_SOFFICE, PATH dirs) are already baked into the command string by the runtime prelude, so nothing legitimate breaks. Adds a regression test asserting secrets are stripped while allowlisted basics pass through. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parent9503c35