Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(mcp,skills,tools): harden untrusted-workspace trust boundary

4 months ago

d9a59c0
Authored
mweinbach6/9/2026, 6:32:42 PM
Opening a malicious repo could drive several actions without consent:

- Workspace .cowork/mcp-servers.json HTTP/SSE servers auto-connected on repo
  open (only stdio was gated), beaconing every tool invocation — which may
  carry file contents/secrets — to an attacker URL with user-config auth
  headers. Broaden the trust gate to ALL workspace-owned transports; rename
  isUntrustedWorkspaceStdioServer -> isUntrustedWorkspaceServer and the opt to
  includeUntrustedWorkspace.
- Project-scope SKILL.md bodies are injected into the model as instructions but
  come from the repo. Frame project (source==="project") skill bodies as
  untrusted; trusted user/global/built-in skills are unchanged.
- Fetched web content is now wrapped in explicit UNTRUSTED markers (prompt-
  injection mitigation).
- The read/glob/grep tools now refuse credential directories (.cowork/auth),
  closing the file-tool exfiltration path for MCP tokens. (bash still has
  full-disk read by the OS-sandbox's documented design.)

Updates workspace-trust, permissions, skill, webFetch, and loadSkillBody tests;
adds positive coverage for each new boundary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parente471e00

11 files changed
  • src/mcp/index.ts+27−19
  • src/server/session/mcp/McpValidationFlow.ts+2−2
  • src/skills/loadSkillBody.ts+21−1
  • src/tools/webFetch.ts+18−1
  • src/utils/permissions.ts+27−0
  • test/mcp.test.ts+9−4
  • test/mcp.workspace-trust.test.ts+21−13
  • test/permissions.test.ts+20−0
  • test/skills.loadSkillBody.test.ts+19−0
  • test/tools/tools.skill.test.ts+5−3
  • test/tools/tools.webFetch.test.ts+6−2