You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(skills): prevent HAR credential leakage - #87958
Prevent the official har-derived-api-client skill from copying captured credentials into agent/model output and reduce exposure of the raw HAR itself. This preserves the scheme/query/header fixes from closed PR #85053 as its original commit (and therefore preserves Tuomas Hietala's authorship), then extends redaction to sensitive query parameters, nested JSON request/response fields, and URL-encoded forms. Both capturers now make completed HARs owner-only on POSIX; the CDP writer also refuses symlink traversal where the platform supports O_NOFOLLOW.
This intentionally does not absorb the capture lifecycle, postData: null, form-without-text, or base64 work in #85100/#84977. Those are separate correctness fixes with overlapping files.
RED proof
With the new behavioral tests kept but the three scripts restored to current origin/main:
A live local capture against JSONPlaceholder also produced mode=600, derived GET /posts/{id}, and completed browserless derivation successfully.
Code path trace
Symptom: running har_to_client.py can place live query/body/response credentials into agent context; capture scripts create raw HARs readable beyond the current user under a typical 022 umask.
Intermediate: the grouping loop previously printed query values and body samples verbatim, while capture output used Playwright/default open() permissions.
Root cause: secret handling covered only selected request headers and documentation warnings; it did not treat structured fields or the raw HAR's filesystem permissions as part of the same credential boundary.
The first commit is the exact commit from closed PR #85053 by @pnaaberi / Tuomas Hietala. This branch builds on it instead of reimplementing the same fixes, preserving authorship in Git history.
AI code review — automated review for reference; please use your judgment.
Review of "fix(skills): prevent HAR credential leakage". Well-layered secret hygiene for a skill whose whole workflow handles live credentials: capture outputs get owner-only permissions with symlink refusal (O_NOFOLLOW on the CDP path plus a pre-check on the Playwright path), the derivation tool redacts credential headers and structured credential fields while HONESTLY documenting that unstructured bodies can still leak, and the SKILL.md guidance shifts from "copy these headers" to "obtain equivalent values from an approved runtime secret source" without pretending the technique bypasses auth. The contributor entry is included. Suggestions:
optional-skills/.../scripts/har_capture.py:51 (TOCTOU asymmetry) — the plain-capture path checks islink BEFORE launching the browser, then lets Playwright create/write the file itself; the CDP path got the stronger O_NOFOLLOW open — aligning both on an os.open-based private write would close the small check-vs-write window too.
nit — consider emitting one stderr line when redaction REPLACED credential material during derive ("redacted N credential headers/fields"), so users know their HAR contained live secrets even if they skip the SKILL.md fine print.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
P3Low — cosmetic, nice to havetool/browserBrowser automation (CDP, Playwright)tool/skillsSkills system (list, view, manage)type/securitySecurity vulnerability or hardening
4 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prevent the official
har-derived-api-clientskill from copying captured credentials into agent/model output and reduce exposure of the raw HAR itself. This preserves the scheme/query/header fixes from closed PR #85053 as its original commit (and therefore preserves Tuomas Hietala's authorship), then extends redaction to sensitive query parameters, nested JSON request/response fields, and URL-encoded forms. Both capturers now make completed HARs owner-only on POSIX; the CDP writer also refuses symlink traversal where the platform supportsO_NOFOLLOW.This intentionally does not absorb the capture lifecycle,
postData: null, form-without-text, or base64 work in #85100/#84977. Those are separate correctness fixes with overlapping files.RED proof
With the new behavioral tests kept but the three scripts restored to current
origin/main:On this branch:
A live local capture against JSONPlaceholder also produced
mode=600, derivedGET /posts/{id}, and completed browserless derivation successfully.Code path trace
har_to_client.pycan place live query/body/response credentials into agent context; capture scripts create raw HARs readable beyond the current user under a typical022umask.open()permissions.Widening audit
token_countremain visible.0600and symlink output is rejected.os.open(..., 0600)writer; existing loose files are tightened and symlinks are rejected whereO_NOFOLLOWexists.Verification
Live smoke:
Attribution
The first commit is the exact commit from closed PR #85053 by @pnaaberi / Tuomas Hietala. This branch builds on it instead of reimplementing the same fixes, preserving authorship in Git history.