Skip to content

agy release summaries can still read local files #653

Description

@JacobStephens2

This was generated by AI during triage.

Context

#605 made the release summary (scripts/release.sh → thirdshift --release-summary) run on the configured Harness. Release input includes contributor-editable PR titles and bodies, which makes it a prompt-injection surface. #605 then took each Harness's summary invocation down to as few tools as its CLI allows:

  • Claude and Grok can't use tools at all.
  • Codex runs read-only with tools disabled.
  • Muse is limited to one model step, so a read can never reach the summary.
  • OpenCode denies every permission.

agy is the remaining gap. Headless agy without --dangerously-skip-permissions auto-denies commands, writes, URLs and MCP. File reads, however, need no permission, and agy has no flag to turn them off. In principle, injected text could make agy read a local secret (for example ~/.gitconfig, or a token file) and quote it in the release notes, which are then published on GitHub.

A probe with real agy 1.3.3, asked to quote ~/.gitconfig, returned no summary, so nothing leaked. That isn't guaranteed across agy versions or models.

Options

  1. Sandbox the summary: run agy's summary under bwrap with an empty HOME and a read-only bind of only what agy needs (its binary plus credentials). Strongest option, but it adds a host dependency to releases (compare thirdshift setup: check that Security sessions can sandbox target code on this machine #608) and needs agy's credential paths.
  2. Exclude agy: when the configured Harness is agy, skip the summary and use GitHub's generated notes (or a fallback Harness). Simple, but agy users lose summaries.
  3. Accept the risk: document it. --review already shows the summary before it's published, and release input comes from merged PRs, which a maintainer has already reviewed.

Decision needed

Which option, or another one? This is a security/product trade-off for the maintainer, not something to hand to an agent yet.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestneeds-triageMaintainer needs to evaluate this issue

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions