mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-09 08:22:19 +02:00
fix(security): keep the post-external-context approval gate on by default
Request authority admits whole tool families from the user's request, so a request to read email also admits send_email, delete_email and bulk_email, and agent processes inherit the host network. With the gate defaulting to off, an instruction injected through an email or a fetched page reaches those tools with no other check; dev refuses them today. Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and pin the production default with a test that imports the module in a fresh interpreter. Four routing tests written for the opt-out posture now set it explicitly.
This commit is contained in:
@@ -488,8 +488,9 @@ VARIABLE_NOTES: dict[str, tuple[str, str, str]] = {
|
||||
# -- Agent loop and tool execution -------------------------------------
|
||||
"ODYSSEUS_TOOL_APPROVAL_GATE": (
|
||||
"Agent loop and tool execution", USER,
|
||||
"Security-relevant. Truthy makes tool calls pass through the approval gate. "
|
||||
"Off by default.",
|
||||
"Security-relevant. On by default: after external content enters a run, "
|
||||
"tools that execute code, mutate state or cause external side effects need "
|
||||
"a separate approval. Set to 0 to opt out.",
|
||||
),
|
||||
"ODYSSEUS_MCP_ALLOWED_COMMANDS": (
|
||||
"Agent loop and tool execution", USER,
|
||||
|
||||
Reference in New Issue
Block a user