Skip to content

fix(skills): harden HAR-derived API output - #85053

Closed
pnaaberi wants to merge 1 commit into
NousResearch:mainfrom
pnaaberi:fix/har-derived-api-safety
Closed

pnaaberi wants to merge 1 commit into
NousResearch:mainfrom
pnaaberi:fix/har-derived-api-safety

Conversation

@pnaaberi

Copy link
Copy Markdown

Summary

Fix three reproducible correctness and secret-handling problems in the optional har-derived-api-client skill:

  • redact credential-bearing request header values in har_to_client.py output;
  • preserve the observed request scheme instead of always printing https://;
  • populate CDP-generated HAR queryString entries, including repeated and blank parameters.

The skill documentation now tells users to obtain current credentials from an approved runtime secret source rather than copying values from a HAR into code or shell history.

Reproduction on current main

A synthetic HTTP HAR with Authorization and X-API-Key headers currently:

  1. prints truncated portions of both credential values;
  2. reports the endpoint as HTTPS even though the observed URL is HTTP.

Separately, _har_entry() in har_capture_cdp.py currently emits an empty queryString array even when the request URL contains query parameters.

Changes

  • classify common authorization/API-key/token/secret header names as sensitive and emit [REDACTED] instead of their values;
  • include url.scheme in endpoint grouping and output;
  • fall back to parsing query parameters from the request URL when a HAR omits queryString;
  • populate CDP HAR queryString from the request URL while preserving repeated and blank values;
  • add offline behavioral regressions for all three cases;
  • clarify credential handling in SKILL.md.

Verification

scripts/run_tests.sh tests/skills/test_har_derived_api_client_skill.py -q
11 passed

python -m py_compile <changed Python files>
python -m ruff check <changed Python files>
git diff --check
All passed

Tested on Linux with Python 3.12. No live credentials or network calls were used.

Scope note

This intentionally does not include the postData: null fix from #84977, so the two pull requests do not overlap.

Adolanium added a commit to Adolanium/hermes-agent that referenced this pull request Aug 13, 2026
Failed --action specs IndexError and skip context.close(), so the HAR
never lands. CDP attach drives pages[0] (and --goto navigates it), and
derivation drops form params and base64 response bodies.

Share a validated run_action helper (bad specs fail with a clear
ValueError, including empty selectors), flush the Playwright HAR in
finally, listen on every CDP context, and open a new tab for --goto so
it cannot wipe the tab Hermes is driving. In-flight requests left after
--wait are flushed as entries with a null response, after detaching the
listeners. Calling the waiting request.response() there could hang the
capture (no timeout) or record a late response twice. har_to_client now
reads params-only postData and decodes base64 content.

Does not change header redaction, scheme printing, or CDP queryString
(NousResearch#85053). Null postData is handled by the new body helper, which
supersedes NousResearch#84977.
@pnaaberi

Copy link
Copy Markdown
Author

Overlap with #85085

The two PRs address different bug classes, but they overlap substantially at the file level.

Both PRs modify:

  • SKILL.md
  • scripts/har_capture_cdp.py
  • scripts/har_to_client.py
  • tests/skills/test_har_derived_api_client_skill.py

A three-way merge of the exact commits produces content conflicts in har_capture_cdp.py, har_to_client.py, and the shared test file. Since #85085 is closed and unmerged, it does not currently block this PR, but its fixes would need manual integration if revived.

Conclusion: different bugs, overlapping implementation areas, not duplicate PRs.

@alt-glitch alt-glitch added type/bug Something isn't working P3 Low — cosmetic, nice to have tool/skills Skills system (list, view, manage) tool/browser Browser automation (CDP, Playwright) labels Aug 13, 2026
@pnaaberi pnaaberi closed this Aug 14, 2026
Adolanium added a commit to Adolanium/hermes-agent that referenced this pull request Oct 1, 2026
Failed --action specs IndexError and skip context.close(), so the HAR
never lands. CDP attach drives pages[0] (and --goto navigates it), and
derivation drops form params and base64 response bodies.

Share a validated run_action helper (bad specs fail with a clear
ValueError, including empty selectors), flush the Playwright HAR in
finally, listen on every CDP context, and open a new tab for --goto so
it cannot wipe the tab Hermes is driving. In-flight requests left after
--wait are flushed as entries with a null response, after detaching the
listeners. Calling the waiting request.response() there could hang the
capture (no timeout) or record a late response twice. har_to_client now
reads params-only postData and decodes base64 content.

Does not change header redaction, scheme printing, or CDP queryString
(NousResearch#85053). Null postData is handled by the new body helper, which
supersedes NousResearch#84977.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low — cosmetic, nice to have tool/browser Browser automation (CDP, Playwright) tool/skills Skills system (list, view, manage) type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants