Conversation
skill_view accepts a file_path parameter to read files within a skill directory, but did not validate the path. Passing file_path="../../.env" allowed reading arbitrary files outside the skill directory, including API keys and other sensitive data. Added path traversal checks matching the existing pattern in skill_manager_tool.py: reject ".." in path components and verify the resolved path stays within the skill directory.
skill_view accepted arbitrary file_path values like '../../.env' and would read files outside the skill directory, exposing API keys and other sensitive data. Added two layers of defense: 1. Reject paths with '..' components (fast, catches obvious traversal) 2. resolve() containment check with trailing '/' to prevent prefix collisions (catches symlinks and edge cases) Fix approach from PR #242 (@Bartok9). Vulnerability reported by @Farukest (#220, PR #221). Tests rewritten to properly mock SKILLS_DIR. Closes #220
|
Thanks for reporting the vulnerability and providing a fix @Farukest! Your test approach (mocking We went with PR #242's code fix because it includes a trailing Fixed in commit 1cb2311. |
Makes sense, the trailing slash guard is a better approach. Thanks for the credit @teknium1 👍 |
Starting WorkBranch: Plan
|
Fixed ✓Commit: Changes Made
VerificationTests: 448 passing ✓
Acceptance Criteria
Note: The Railway deployment has the API configured, so it correctly shows AI options. In local dev without API key, users will see "Templates only (AI not configured)" instead of the misleading AI options. |
…usResearch#220) skill_view accepted arbitrary file_path values like '../../.env' and would read files outside the skill directory, exposing API keys and other sensitive data. Added two layers of defense: 1. Reject paths with '..' components (fast, catches obvious traversal) 2. resolve() containment check with trailing '/' to prevent prefix collisions (catches symlinks and edge cases) Fix approach from PR NousResearch#242 (@Bartok9). Vulnerability reported by @Farukest (NousResearch#220, PR NousResearch#221). Tests rewritten to properly mock SKILLS_DIR. Closes NousResearch#220
…usResearch#220) skill_view accepted arbitrary file_path values like '../../.env' and would read files outside the skill directory, exposing API keys and other sensitive data. Added two layers of defense: 1. Reject paths with '..' components (fast, catches obvious traversal) 2. resolve() containment check with trailing '/' to prevent prefix collisions (catches symlinks and edge cases) Fix approach from PR NousResearch#242 (@Bartok9). Vulnerability reported by @Farukest (NousResearch#220, PR NousResearch#221). Tests rewritten to properly mock SKILLS_DIR. Closes NousResearch#220
…ecycle Acting implementation lane: Talos; review authority: Athena; control: Hermes.\n\nGitHub Issue: dagyrox/or7-platform#221\nHermes Kanban: t_c27eaab4; repair t_2c98e44f run 123\nCanonical work packet: https://github.com/dagyrox/or7-platform/issues/221\nPlanned tracked packet: docs/agentic-operations/work-packets/2026-08-21-hermes-kanban-lifecycle-isolation.md via t_b4fe713f\nExact reviewed head: aedc1ef\nAthena verdict artifact: /tmp/athena-hermes-pr9-body-rereview-aedc1efc.md (93b549ad9c8ab58e43210b6a898bab918c212695e743375a1e0268c6ab21fa7a)\nATHENA_VERDICT: READY_TO_MERGE
|
Provider fix opened as #93727. It adds the exact embedded-dispatcher quiesce/acknowledgment boundary, fixed fail-closed CLI states, cancellation-safe drain behavior, and runbook documentation. Acting lane: Talos builder; Hermes Kanban: t_c349e5f1; run: run-20260824-issue-221. |
[Talos][Or7 NousResearch#221][Hermes PR #10] Reject bool/float protocol and PID values across owner, request, and ACK trust-boundary validation. Malformed owner state now makes the requester fail closed without control writes; deterministic red-green coverage preserves valid different-generation behavior.\n\nHermes Kanban: t_832c4f2d / run 178\nWork packet: /root/projects/or7-platform/.worktrees/issue221-activation-freeze-repair/docs/agentic-operations/work-packets/2026-08-21-hermes-kanban-lifecycle-isolation.md\nAuthority: Athena; Control: Hermes; Acting lane: Talos
* fix(kanban): add fail-closed embedded dispatcher quiesce Acting lane: Talos builder Issue: dagyrox/or7-platform#221 Consumer PR: dagyrox/or7-platform#223 Hermes Kanban: t_c349e5f1 / run 173 Work packet: docs/agentic-operations/work-packets/2026-08-21-hermes-kanban-lifecycle-isolation.md * fix(kanban): reject malformed quiesce records Acting lane: Talos builder Authority: Athena architecture/release review Issue: dagyrox/or7-platform#221 Provider PR: #10 Hermes Kanban: t_48ce0768 / run 176 Predecessor: 6882b31 Review artifact: /tmp/athena-hermes-pr10-exact-head-6882b314.md (SHA-256 3cbf369b32f23b5f6ef5149e48904fbea32314895de06afa91b1a4ce0bf996af) Work packet: docs/agentic-operations/work-packets/2026-08-21-hermes-kanban-lifecycle-isolation.md * fix(kanban): enforce exact control integer types [Talos][Or7 NousResearch#221][Hermes PR #10] Reject bool/float protocol and PID values across owner, request, and ACK trust-boundary validation. Malformed owner state now makes the requester fail closed without control writes; deterministic red-green coverage preserves valid different-generation behavior.\n\nHermes Kanban: t_832c4f2d / run 178\nWork packet: /root/projects/or7-platform/.worktrees/issue221-activation-freeze-repair/docs/agentic-operations/work-packets/2026-08-21-hermes-kanban-lifecycle-isolation.md\nAuthority: Athena; Control: Hermes; Acting lane: Talos --------- Co-authored-by: Talos <11076310+dagyrox@users.noreply.github.com>
…usResearch#220) skill_view accepted arbitrary file_path values like '../../.env' and would read files outside the skill directory, exposing API keys and other sensitive data. Added two layers of defense: 1. Reject paths with '..' components (fast, catches obvious traversal) 2. resolve() containment check with trailing '/' to prevent prefix collisions (catches symlinks and edge cases) Fix approach from PR NousResearch#242 (@Bartok9). Vulnerability reported by @Farukest (NousResearch#220, PR NousResearch#221). Tests rewritten to properly mock SKILLS_DIR. Closes NousResearch#220
…usResearch#220) skill_view accepted arbitrary file_path values like '../../.env' and would read files outside the skill directory, exposing API keys and other sensitive data. Added two layers of defense: 1. Reject paths with '..' components (fast, catches obvious traversal) 2. resolve() containment check with trailing '/' to prevent prefix collisions (catches symlinks and edge cases) Fix approach from PR NousResearch#242 (@Bartok9). Vulnerability reported by @Farukest (NousResearch#220, PR NousResearch#221). Tests rewritten to properly mock SKILLS_DIR. Closes NousResearch#220
skill_viewaccepts afile_pathparameter to read files within a skill directory, but does not validate the path for traversal.skill_view("any-skill", file_path="../../.env")reads~/.hermes/.envcontaining API keys.Changes
Added path traversal checks to
tools/skills_tool.pymatching the existing pattern inskill_manager_tool.py:..in path componentsresolve()containment checkTests
Added
tests/tools/test_skill_view_traversal.pywith 4 tests:../../.envis blockedreferences/../../.envis blockedfile_pathstill worksAll 4 tests pass.
Closes #220