Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(sandbox): review round 2 — escalation floor, shell resolve, docs, handle leak

4 months ago

5eb57f3
Authored
Claude6/5/2026, 3:45:28 AM
Cursor Bugbot (commit bb177ef) fixes:
- bash.ts: never escalate a read-only policy to danger-full-access on a
  sandbox-denied failure — only workspace-write may be lifted, preserving the
  read-only floor for explorer/reviewer/research roles (High).
- bash.ts: when sandboxed, resolve the inner shell to a concrete program before
  wrapping (absolute-exists or bare name found on PATH, incl. Windows exts), so
  machines with only powershell.exe no longer fail under the sandbox.
- bash.ts: correct the child targetPaths description — scope is enforced by the
  OS sandbox (writes), not by static command parsing; reads aren't path-scoped.
- cowork-win-sandbox: release all Win32 handles on wait/exit-code failure paths.

Verified: bun run check, typecheck, tests (incl. new read-only-no-escalation
test), crate build.

Parentbb177ef

3 files changed
  • crates/cowork-win-sandbox/src/main.rs+12−8
  • src/tools/bash.ts+46−5
  • test/tools/tools.bash.test.ts+20−0