Skip to content

fix(profile): classify every tool; boundary tests fail on unclassified ones - #48

Merged
chaodu-agent merged 1 commit into
mainfrom
fix/exhaustive-tool-classification
Sep 30, 2026
Merged

chaodu-agent merged 1 commit into
mainfrom
fix/exhaustive-tool-classification

Conversation

@chaodu-agent

Copy link
Copy Markdown
Contributor

From an external review of docs/tool-profiles.md (point 1 and point 4; points 2–3 recorded on #45).

Problem. ProfileBoundaryTests decided "reaches a shell" from a hand-written list (osascript, key, mouse + exec*). A new tool such as clipboard_write would be scanned but counted as safe, so a future non-shell profile could allow it and still pass. The scan itself was a regex over let name = "…", which misses other declarations.

Fix.

  • Every served tool is classified observe / act / shell (ToolProfile.localToolClass; Linux LOCAL_TOOL_CLASS). Tests fail on any unclassified tool, on stale entries, on a non-shell-equivalent profile allowing a shell tool, and on observe holding non-observe tools.
  • macOS: new ToolCatalog.local is the single list main.swift serves and the tests check; the source scan remains as a cross-check that nothing is served from outside the catalog.
  • Linux: same classes; tests run over the actual tool_list output and require it to match LOCAL_TOOL_NAMES.
  • observe at runtime now requires allowlist and observe class on both platforms.
  • Docs: observe protects the computer, not the agent — screenshots can carry prompt injection.

Verified. macOS 118/118, Linux 18/18, clippy -D warnings clean. Mutation: adding an unclassified clipboard_write fails testEveryServedToolIsClassified (macOS) and every_served_tool_is_classified_and_the_lists_agree (Linux) with the tool named. No behaviour change for existing profiles.

Refs #45.

…d ones (#45)

The shell-capable list was hand-maintained: a new tool (say clipboard_write)
would be scanned but treated as safe. Every served tool now has a class
(observe / act / shell) and the tests fail on an unclassified tool, on a
non-shell-equivalent profile allowing a shell tool, and on observe holding
anything but observe tools. macOS: ToolCatalog is the single list main.swift
serves and the tests check (source scan kept as a cross-check). Linux: same
classes and checks over tool_list. observe now requires allowlist AND
observe class at runtime. Docs: observe protects the computer, not the agent
(screenshots can carry prompt injection). Mutation-checked on both sides.
@chaodu-agent
chaodu-agent merged commit 1b66fb7 into main Sep 30, 2026
6 checks passed
@chaodu-agent
chaodu-agent deleted the fix/exhaustive-tool-classification branch September 30, 2026 20:17
chaodu-agent added a commit that referenced this pull request Sep 30, 2026
…computer, not the agent (#49)

Missed from #48 (the doc edit landed after that commit was staged).

Co-authored-by: chaodu-agent <274062505+chaodu-agent@users.noreply.github.com>
@chaodu-agent

Copy link
Copy Markdown
Contributor Author

Note: the docs/tool-profiles.md change described above landed separately in #49 (it was not staged when this was committed).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant