Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): strip secrets from sandboxed shell env via allowlist

4 months ago

28b9854
Authored
mweinbach6/9/2026, 6:04:57 PM
The env allowlist (minimalSandboxEnv/SANDBOX_ENV_ALLOWLIST) was unreachable:
the sandboxed spawn used `opts.env ?? minimalSandboxEnv()`, but opts.env
(ctx.toolEnv) is always a full clone of process.env, so the allowlist never
ran. Every sandboxed command therefore received the server's entire env,
including ANTHROPIC_API_KEY and other provider secrets. The OS sandbox confines
writes but not env reads, and network is allowed by default, so an auto-approved
command could exfiltrate keys (curl ...$ANTHROPIC_API_KEY).

Filter the sandboxed child env to the allowlist applied to toolEnv. Runtime
vars the command needs (COWORK_ARTIFACT_RUNTIME_*, COWORK_SOFFICE, PATH dirs)
are already baked into the command string by the runtime prelude, so nothing
legitimate breaks. Adds a regression test asserting secrets are stripped while
allowlisted basics pass through.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parent9503c35

2 files changed
  • src/tools/bash.ts+10−3
  • test/tools/tools.bash.test.ts+36−0