Request authority admits whole tool families from the user's request, so a
request to read email also admits send_email, delete_email and bulk_email,
and agent processes inherit the host network. With the gate defaulting to
off, an instruction injected through an email or a fetched page reaches those
tools with no other check; dev refuses them today.
Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and
pin the production default with a test that imports the module in a fresh
interpreter. Four routing tests written for the opt-out posture now set it
explicitly.
- Enforce outbound URL policy on all hops via bounded manual redirects in scholarly lookups
- Guard declared Content-Length in EditorDraftRoute before request body parsing
- Keep scholarly lookup timeouts and budgets as internal constants rather than surface env vars
- Narrow TUI threat-model description around demonstrable host shell bridge behavior
- Add behavioral regression tests for redirect security and pre-parsing body size guards
The post-external-context gate is off unless ODYSSEUS_TOOL_APPROVAL_GATE is
set, but THREAT_MODEL.md described only the untrusted-context wrapper. A reader
auditing the prompt-injection posture would reasonably assume the gate was
active.
State the default, what it blocks when enabled, the two deliberate exemptions,
and note in Known Gaps that the compensating control for the missing shell
sandbox is off by default.