[Reborn] Envelope installed skill prompt context - #3505
serrrfirat wants to merge 3 commits into
Conversation
There was a problem hiding this comment.
Code Review
This pull request centralizes the sanitization and enveloping of untrusted content into a new untrusted_context module. It modifies Installed skills to include sanitized prompt content within an explicit untrusted envelope, whereas this content was previously excluded. Reviewer feedback recommends making the prefix method pub(crate) to avoid string duplication, replacing hardcoded byte limits with shared constants, and using the UntrustedContextKind::prefix method as the single source of truth for prefixes.
| } | ||
|
|
||
| impl UntrustedContextKind { | ||
| const fn prefix(self) -> &'static str { |
There was a problem hiding this comment.
Make this method pub(crate) so it can be used by other modules in the crate (e.g., skill_context.rs) to avoid duplicating the prefix strings and maintain consistency.
| const fn prefix(self) -> &'static str { | |
| pub(crate) const fn prefix(self) -> &'static str { |
References
- Use centralized helper functions for security-sensitive logic to ensure consistency and avoid duplication.
| SkillTrustLevel::Installed => None, | ||
| SkillTrustLevel::Installed => { | ||
| let summary = | ||
| untrusted_context_summary(UntrustedContextKind::Skill, &parsed.prompt_content, 512) |
There was a problem hiding this comment.
The value 512 is used as a hardcoded limit for untrusted skill content. Always truncate tool output for previews or status updates to a reasonable maximum length. Consider defining a shared constant for this limit to maintain consistency across the repository.
References
- Always truncate tool output for previews or status updates to a reasonable maximum length.
- Use centralized helper functions for security-sensitive logic to ensure consistency and avoid duplication.
| const DEFAULT_MAX_SKILL_CONTEXT_BYTES: usize = 32 * 1024; | ||
| const FNV_OFFSET: u64 = 0xcbf29ce484222325; | ||
| const FNV_PRIME: u64 = 0x00000100000001B3; | ||
| const UNTRUSTED_SKILL_PREFIX: &str = "Untrusted skill content: "; |
There was a problem hiding this comment.
The UNTRUSTED_SKILL_PREFIX string is duplicated here. To improve maintainability and ensure consistency, use the UntrustedContextKind::prefix method as the single source of truth.
| const UNTRUSTED_SKILL_PREFIX: &str = "Untrusted skill content: "; | |
| const UNTRUSTED_SKILL_PREFIX: &str = UntrustedContextKind::Skill.prefix(); |
References
- Use centralized helper functions for security-sensitive logic to ensure consistency and avoid duplication.
|
Paranoid review found Medium+ issues at head
|
|
Closing this version. Direction changed: instead of runtime hard-rejecting installed skill prompt content, we should move suspicious-skill handling to install/discovery time with quarantine/review UX, hash-scoped trust decisions, and runtime-safe fallback that never emits unsafe raw content. |
Summary
Untrusted skill content: ...Scope
Follow-up to #3476. Addresses the #3492 comment item: SKILL.md prompt content for Installed skills needs the same baseline untrusted-content envelope primitive as memory.
Verification
CARGO_TARGET_DIR=/Users/firatsertgoz/Documents/ironclaw/target cargo test -p ironclaw_loop_support -p ironclaw_host_runtime -p ironclaw_turnsCARGO_TARGET_DIR=/Users/firatsertgoz/Documents/ironclaw/target cargo test -p ironclaw_architectureDoes not close #3492.