Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

feat(sandbox): inline sandbox-aware approval UX + global skill/plugin read coverage

4 months ago

7bff7fa
Authored
mweinbach6/5/2026, 11:10:11 PM
Replace the generic global "Command approval" modal for sandbox-denial
escalations with a clean, inline approve/deny card in the chat feed (all
workspaces). Enrich the approval contract end to end with sandbox `detail` +
`category` (filesystem/network) so clients can frame the decision as "re-run
with full access?" instead of a raw risk code. Ordinary (requires_manual_review)
approvals still use the modal; humanize its risk-code copy.

Also prove and document that agents can read global skills/plugins under
~/.cowork (skills dir, ~/.cowork/plugins, discovered plugin skill paths) inside
the OS sandbox (read-only) and via the file tools, including scoped children;
clarify that .agents/ is the marketplace source layout, not a runtime namespace.

Co-authored-by: Cursor <cursoragent@cursor.com>

Parentc4ceed8

37 files changed
  • apps/desktop/src/app/store.actions/thread.ts+15−1
  • apps/desktop/src/app/store.helpers.ts+7−0
  • apps/desktop/src/app/store.helpers/threadEventReducer/handlers/lifecycleHandlers.ts+24−1
  • apps/desktop/src/app/store.helpers/threadEventReducer/jsonRpcWorkspace.ts+16−0
  • apps/desktop/src/app/store.helpers/threadEventReducerContext.ts+2−0
  • apps/desktop/src/app/store.ts+1−0
  • apps/desktop/src/app/types.ts+13−0
  • apps/desktop/src/ui/ChatView.tsx+13−0
  • apps/desktop/src/ui/PromptModal.tsx+19−1
  • apps/desktop/src/ui/chat/ChatFeed.tsx+18−0
  • apps/desktop/src/ui/chat/SandboxApprovalCard.tsx+66−0
  • apps/desktop/test/protocol-v2-events.test.ts+45−0
  • apps/desktop/test/sandbox-approval-card.test.tsx+85−0
  • docs/generated/websocket-jsonrpc.d.ts+1−1
  • docs/generated/websocket-jsonrpc.schema.json+1−1
  • docs/sandbox.md+20−0
  • docs/websocket-protocol.md+7−1
  • src/agent.ts+2−1
  • src/platform/sandbox/denied.ts+31−0
  • src/platform/sandbox/index.ts+1−1
  • src/runtime/types.ts+2−2
  • src/server/jsonrpc/schema.threadTurn.ts+4−0
  • src/server/projection/conversationProjectionSessionEvents.ts+2−0
  • src/server/projection/conversationProjectionTypes.ts+2−0
  • src/server/protocol.ts+8−0
  • src/server/session/InteractionManager.ts+6−1
  • src/server/session/turnExecution/runTurnInvocation.ts+2−2
  • src/server/session/turnExecution/runUserMessageTurn.ts+2−2
  • src/tools/bash.ts+17−2
  • src/tools/context.ts+2−2
  • src/types.ts+18−0
  • test/jsonrpc/flow.prompts.test.ts+46−0
  • test/permissions.test.ts+54−0
  • test/platform/sandbox.enforcement.integration.test.ts+43−0
  • test/platform/sandbox.test.ts+43−1
  • test/server/interactionManager.approval.test.ts+27−0
  • test/tools/tools.bash.test.ts+30−1