Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(sandbox): enforce OS sandbox in bash tool; replace parse-based filtering

4 months ago

3bfd6d9
Authored
Claude6/5/2026, 3:14:01 AM
Wire the SandboxManager into the bash tool and switch from pre-run command
filtering to OS-level enforcement with escalate-on-failure, modeled on Codex:

- bash.ts: resolve SandboxPolicy, run the command wrapped by the platform
  sandbox, and only prompt (to retry unsandboxed) when a sandboxed run fails
  in a way that looks like a sandbox denial (isLikelySandboxDenied).
- agent.ts: resolve sandboxPolicy from role + config + targetPaths onto ToolContext.
- config: add AgentConfig.sandbox ({ mode, network }) + AGENT_SANDBOX env override
  + config/defaults.json default (workspace-write, network enabled).
- InteractionManager.approveCommand: becomes a sandbox-escalation prompt (no more
  regex classification); add sandbox_denied_escalation risk code.
- Remove the bypassable parse-based filtering: gut commandPolicy.ts to the
  AgentShellPolicy type alias, delete src/utils/approval.ts.
- Update tests for escalate-on-failure; regenerate JSON-RPC schema.

Verified: full suite has identical residual failures to base (2 pre-existing
desktop DOM/ordering fails); typecheck + docs:check green.

Parentfcccc11

16 files changed
  • biome.json+1−3
  • config/defaults.json+4−0
  • docs/generated/websocket-jsonrpc.d.ts+2−2
  • docs/generated/websocket-jsonrpc.schema.json+1−1
  • src/agent.ts+11−1
  • src/config.ts+30−0
  • src/server/agents/commandPolicy.ts+11−1267
  • src/server/session/InteractionManager.ts+12−18
  • src/tools/bash.ts+104−78
  • src/tools/context.ts+9−1
  • src/types.ts+9−0
  • src/utils/approval.ts+0−259
  • test/approval.test.ts+0−580
  • test/bash.readonly-policy.test.ts+0−305
  • test/session/agentSession.lifecycle.test.ts+6−45
  • test/tools/tools.bash.test.ts+55−17