fix(security): keep the post-external-context approval gate on by default

Request authority admits whole tool families from the user's request, so a
request to read email also admits send_email, delete_email and bulk_email,
and agent processes inherit the host network. With the gate defaulting to
off, an instruction injected through an email or a fetched page reaches those
tools with no other check; dev refuses them today.

Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and
pin the production default with a test that imports the module in a fresh
interpreter. Four routing tests written for the opt-out posture now set it
explicitly.
This commit is contained in:
Léo
2026-10-06 19:49:15 +02:00
parent 8f0a28c05e
commit ee13ed1eee
8 changed files with 80 additions and 13 deletions
+3 -2
View File
@@ -488,8 +488,9 @@ VARIABLE_NOTES: dict[str, tuple[str, str, str]] = {
# -- Agent loop and tool execution -------------------------------------
"ODYSSEUS_TOOL_APPROVAL_GATE": (
"Agent loop and tool execution", USER,
"Security-relevant. Truthy makes tool calls pass through the approval gate. "
"Off by default.",
"Security-relevant. On by default: after external content enters a run, "
"tools that execute code, mutate state or cause external side effects need "
"a separate approval. Set to 0 to opt out.",
),
"ODYSSEUS_MCP_ALLOWED_COMMANDS": (
"Agent loop and tool execution", USER,