Repository navigation
fix(sdk): isolate local agent credentials from authored code - #596
Conversation
Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (24)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe SDK now reads validated provider credentials from an inherited file descriptor and passes the resulting environment to flow checks, authored flows, and worker subprocesses. Cloud artifact manifests now declare and validate the matching runtime capability. ChangesLocal agent environment forwarding
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant CLI
participant localAgentEnvironment
participant AgentWorker
participant runAgentCli
participant ProviderCLI
CLI->>localAgentEnvironment: Read and validate descriptor credentials
localAgentEnvironment-->>CLI: Return credential overlay
CLI->>AgentWorker: Attach with environment
AgentWorker->>runAgentCli: Run with processEnvironment
runAgentCli->>ProviderCLI: Spawn with supplied environment
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The credential handoff and environment forwarding are consistent with the isolation objective, and artifact verification requires the matching runtime capability. No concrete merge-blocking issue remains; merge after normal checks pass. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The handoff reduces credential exposure through the flow’s environment, but readiness checks can still pass those credentials to flow-selected executables. Production exposure depends on host-side executable and credential controls that remain unverified. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the keys with care Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
Devin Review found 4 potential issues.
2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 77bc039. Configure here.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 77bc0393e7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |

Summary
Security contract
House/provider secrets never enter the flows process environment. The host writes a bounded JSON environment to fd 3, the SDK synchronously reads and closes it before any authored source import, and only provider subprocesses receive the merged values.
Validation
Note
High Risk
Changes authentication and secret handling across run, resume, preflight, and subprocess boundaries; misconfiguration could break probes or leak credentials if validation regresses.
Overview
Introduces isolated provider credentials for local agent/LLM work so authored flow code never sees house API keys in
process.env.The host can pass secrets via
FLOWS_LOCAL_AGENT_ENV_FD: the SDK reads a bounded JSON payload from that inherited descriptor before authored modules load, removes the marker from the environment, and fails closed on invalid or non-allowlisted keys (provider API keys/base URLs only).That merged
agentEnvironmentis threaded explicitly throughflows run/ resume / direct run, durable authored execution, CLI auth/model preflight probes, local agent and LLM workers, communication agents, andrunAgentCli—instead of relying on ambientprocess.env. Across the authored Node child, only the credential overlay is serialized; the child validates the handoff and keeps PATH/NODE_OPTIONSon inherited values.Cloud artifacts now declare capability
local-agent-env-fd-v1so runtimes without this contract are rejected at verify time.Reviewed by Cursor Bugbot for commit 27a0115. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Isolates local agent credentials from authored code by passing house/provider secrets to provider subprocesses, CLI/auth probes, and communication workers through a one-use inherited file descriptor instead of the process environment.
local-agent-env-fd-v1capability.Written for commit 27a0115. Summary will update on new commits.