You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
agy release summaries can still read local files #653
#605 made the release summary (scripts/release.sh → thirdshift --release-summary) run on the configured Harness. Release input includes contributor-editable PR titles and bodies, which makes it a prompt-injection surface. #605 then took each Harness's summary invocation down to as few tools as its CLI allows:
Claude and Grok can't use tools at all.
Codex runs read-only with tools disabled.
Muse is limited to one model step, so a read can never reach the summary.
OpenCode denies every permission.
agy is the remaining gap. Headless agy without --dangerously-skip-permissions auto-denies commands, writes, URLs and MCP. File reads, however, need no permission, and agy has no flag to turn them off. In principle, injected text could make agy read a local secret (for example ~/.gitconfig, or a token file) and quote it in the release notes, which are then published on GitHub.
A probe with real agy 1.3.3, asked to quote ~/.gitconfig, returned no summary, so nothing leaked. That isn't guaranteed across agy versions or models.
Exclude agy: when the configured Harness is agy, skip the summary and use GitHub's generated notes (or a fallback Harness). Simple, but agy users lose summaries.
Accept the risk: document it. --review already shows the summary before it's published, and release input comes from merged PRs, which a maintainer has already reviewed.
Decision needed
Which option, or another one? This is a security/product trade-off for the maintainer, not something to hand to an agent yet.
Context
#605 made the release summary (
scripts/release.sh→thirdshift --release-summary) run on the configured Harness. Release input includes contributor-editable PR titles and bodies, which makes it a prompt-injection surface. #605 then took each Harness's summary invocation down to as few tools as its CLI allows:agy is the remaining gap. Headless agy without
--dangerously-skip-permissionsauto-denies commands, writes, URLs and MCP. File reads, however, need no permission, and agy has no flag to turn them off. In principle, injected text could make agy read a local secret (for example~/.gitconfig, or a token file) and quote it in the release notes, which are then published on GitHub.A probe with real agy 1.3.3, asked to quote
~/.gitconfig, returned no summary, so nothing leaked. That isn't guaranteed across agy versions or models.Options
bwrapwith an empty HOME and a read-only bind of only what agy needs (its binary plus credentials). Strongest option, but it adds a host dependency to releases (compare thirdshift setup: check that Security sessions can sandbox target code on this machine #608) and needs agy's credential paths.--reviewalready shows the summary before it's published, and release input comes from merged PRs, which a maintainer has already reviewed.Decision needed
Which option, or another one? This is a security/product trade-off for the maintainer, not something to hand to an agent yet.