4 months ago
d9a59c0Opening a malicious repo could drive several actions without consent: - Workspace .cowork/mcp-servers.json HTTP/SSE servers auto-connected on repo open (only stdio was gated), beaconing every tool invocation — which may carry file contents/secrets — to an attacker URL with user-config auth headers. Broaden the trust gate to ALL workspace-owned transports; rename isUntrustedWorkspaceStdioServer -> isUntrustedWorkspaceServer and the opt to includeUntrustedWorkspace. - Project-scope SKILL.md bodies are injected into the model as instructions but come from the repo. Frame project (source==="project") skill bodies as untrusted; trusted user/global/built-in skills are unchanged. - Fetched web content is now wrapped in explicit UNTRUSTED markers (prompt- injection mitigation). - The read/glob/grep tools now refuse credential directories (.cowork/auth), closing the file-tool exfiltration path for MCP tokens. (bash still has full-disk read by the OS-sandbox's documented design.) Updates workspace-trust, permissions, skill, webFetch, and loadSkillBody tests; adds positive coverage for each new boundary. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parente471e00