Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

revert(tools): don't gate agent web tools on the shell-sandbox network policy

3 months ago

f6618e7
Authored
mweinbach6/9/2026, 11:43:44 PM
The sandbox `network: false` policy constrains the bash shell sandbox (the
executed command's network access) — it is NOT meant to disable the agent's
own first-party tools. This PR had wrongly coupled them, so a no-network
session also lost webFetch, webSearch, and Gemini's provider-native web
search. MCP was never gated and stays working.

Reverts:
- webFetch/webSearch: drop the policyAllowsNetwork execute guards.
- google-native: drop the networkAllowed threading (agent.ts, runtime types,
  buildGoogleStreamOptions) so provider-native web search follows the user's
  nativeWebSearch setting, not the shell sandbox.
- remove the tests that asserted the old (incorrect) gating.

bash shell-sandbox network enforcement is unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parent28903fd

7 files changed
  • src/agent.ts+1−5
  • src/runtime/googleInteractionsRuntime.ts+1−7
  • src/runtime/types.ts+0−7
  • src/tools/webFetch.ts+0−8
  • src/tools/webSearch.ts+0−9
  • test/runtime/google-native/unit.request.test.ts+0−43
  • test/tools/tools.webFetch.test.ts+0−25