mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-08 16:02:20 +02:00
fix(security): keep the post-external-context approval gate on by default
Request authority admits whole tool families from the user's request, so a request to read email also admits send_email, delete_email and bulk_email, and agent processes inherit the host network. With the gate defaulting to off, an instruction injected through an email or a fetched page reaches those tools with no other check; dev refuses them today. Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and pin the production default with a test that imports the module in a fresh interpreter. Four routing tests written for the opt-out posture now set it explicitly.
This commit is contained in:
@@ -678,9 +678,13 @@ POST_EXTERNAL_BLOCKED_EFFECTS = frozenset(
|
||||
)
|
||||
|
||||
|
||||
# On by default: until agent processes run without network and side-effecting
|
||||
# non-process tools have their own exact-approval boundary, this gate is the
|
||||
# only check between injected external content and those tools. Set it to a
|
||||
# falsy value to opt out.
|
||||
TOOL_APPROVAL_GATE_ENABLED = (
|
||||
str(os.getenv("ODYSSEUS_TOOL_APPROVAL_GATE", "0")).strip().lower()
|
||||
in {"1", "true", "yes", "on"}
|
||||
str(os.getenv("ODYSSEUS_TOOL_APPROVAL_GATE", "1")).strip().lower()
|
||||
not in {"0", "false", "no", "off"}
|
||||
)
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user