4 months ago
ebe8bf3Follow-up hardening from a review of the branch: - webFetch: cancel the response stream on over-cap throw (was leaking the connection like the download path already guards against), decode incrementally to halve peak memory, and cap the null-body fallback. - webFetch: defang an embedded end-marker / sanitize the URL so attacker page content cannot break out of the untrusted-content frame. - mcp: cap nested schema property/enum descriptions, not just the top-level tool description, so a hostile server cannot inject a large payload via a nested description. - skills: keep the operator-authored policy overlay OUTSIDE the untrusted project-skill frame; add an exception line to the referenced-skill injection/steer headers so the "authoritative" wrapper no longer contradicts the inner untrusted framing. - permissions: canonicalize credential deny dirs so a workspace symlink into .cowork/auth cannot bypass the block when the workspace path is itself symlinked (e.g. macOS /var -> /private/var). - edit: reject a replaceAll whose projected result would exceed the file cap before building the string (heap-exhaustion guard). - cleanup: move stranded imports to the top of AgentControl; extract the duplicated withRequestTimeout helper into src/utils/abortSignal. Adds regression tests for each behavioral fix. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parentf4906ee