Skip to content

fix(sdk): isolate local agent credentials from authored code - #596

Merged
khaliqgant merged 3 commits into
mainfrom
fix/house-authored-credential-isolation
Sep 30, 2026
Merged

khaliqgant merged 3 commits into
mainfrom
fix/house-authored-credential-isolation

Conversation

@khaliqgant

@khaliqgant khaliqgant commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

  • consume a one-use inherited descriptor before authored TypeScript is imported
  • remove the descriptor capability from the runtime environment
  • pass the isolated environment only to local agent and LLM provider subprocesses

Security contract

House/provider secrets never enter the flows process environment. The host writes a bounded JSON environment to fd 3, the SDK synchronously reads and closes it before any authored source import, and only provider subprocesses receive the merged values.

Validation

  • npm exec --no -- vitest run tests/local-agent-environment.test.ts tests/worker-cli.test.ts (24 passed)
  • npm run typecheck
  • npm run typecheck:tests
  • full npm test: 3,479 passed; macOS-only run has 49 failures in Linux sandbox isolation and missing duplicated kernel target paths, unrelated to this change; the new isolation suite passed

Note

High Risk
Changes authentication and secret handling across run, resume, preflight, and subprocess boundaries; misconfiguration could break probes or leak credentials if validation regresses.

Overview
Introduces isolated provider credentials for local agent/LLM work so authored flow code never sees house API keys in process.env.

The host can pass secrets via FLOWS_LOCAL_AGENT_ENV_FD: the SDK reads a bounded JSON payload from that inherited descriptor before authored modules load, removes the marker from the environment, and fails closed on invalid or non-allowlisted keys (provider API keys/base URLs only).

That merged agentEnvironment is threaded explicitly through flows run / resume / direct run, durable authored execution, CLI auth/model preflight probes, local agent and LLM workers, communication agents, and runAgentCli—instead of relying on ambient process.env. Across the authored Node child, only the credential overlay is serialized; the child validates the handoff and keeps PATH/NODE_OPTIONS on inherited values.

Cloud artifacts now declare capability local-agent-env-fd-v1 so runtimes without this contract are rejected at verify time.

Reviewed by Cursor Bugbot for commit 27a0115. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Isolates local agent credentials from authored code by passing house/provider secrets to provider subprocesses, CLI/auth probes, and communication workers through a one-use inherited file descriptor instead of the process environment.

  • The descriptor is read and closed synchronously before any authored source is imported, so authored code can never inherit or read the credentials.
  • The merged environment is passed explicitly only to local agent, LLM worker, communication, and provider preflight probe subprocesses.
  • Only allowlisted provider credential keys may cross the authored runtime boundary; invalid descriptors or malformed payloads fail closed at startup.
  • Cloud artifacts now advertise the local-agent-env-fd-v1 capability.

Written for commit 27a0115. Summary will update on new commits.

Review in cubic

Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f87e6aa0-83e1-4cf9-944a-816d0f754f90

📥 Commits

Reviewing files that changed from the base of the PR and between 5cf0b47 and 27a0115.

📒 Files selected for processing (24)
  • packages/sdk/src/authored-flow-executor.ts
  • packages/sdk/src/authored-node-entry.ts
  • packages/sdk/src/authored-node-runner.ts
  • packages/sdk/src/authored-preflight.ts
  • packages/sdk/src/authored-root.ts
  • packages/sdk/src/authored-worker-step.ts
  • packages/sdk/src/cli/check.ts
  • packages/sdk/src/cli/cli-probe.ts
  • packages/sdk/src/cli/direct-run.ts
  • packages/sdk/src/cli/run.ts
  • packages/sdk/src/communication/local.ts
  • packages/sdk/src/communication/worker.ts
  • packages/sdk/src/llm-worker.ts
  • packages/sdk/src/local-agent-environment.ts
  • packages/sdk/src/local-agent.ts
  • packages/sdk/src/worker-cli.ts
  • packages/sdk/src/worker.ts
  • packages/sdk/tests/authored-preflight.test.ts
  • packages/sdk/tests/cli-probe.test.ts
  • packages/sdk/tests/communication-worker.test.ts
  • packages/sdk/tests/local-agent-environment.test.ts
  • packages/sdk/tests/worker-cli.test.ts
  • scripts/cloud-artifact.mjs
  • scripts/cloud-artifact.test.mjs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The SDK now reads validated provider credentials from an inherited file descriptor and passes the resulting environment to flow checks, authored flows, and worker subprocesses. Cloud artifact manifests now declare and validate the matching runtime capability.

Changes

Local agent environment forwarding

Layer / File(s) Summary
Credential validation and authored-flow handoff
packages/sdk/src/local-agent-environment.ts, packages/sdk/src/authored-*, packages/sdk/tests/local-agent-environment.test.ts, packages/sdk/tests/authored-preflight.test.ts
The SDK accepts credential-only environment values from an inherited descriptor and passes them through authored-flow execution and child Node requests. Tests cover credential validation, descriptor handling, and authored preflight.
CLI environment capture and probes
packages/sdk/src/cli/*, packages/sdk/src/cli/check.ts, packages/sdk/src/cli/cli-probe.ts, packages/sdk/tests/cli-probe.test.ts
Run, resume, and direct-flow paths pass the captured environment to flow checks and worker attachments. Executable lookup and provider probes use the supplied environment.
Worker and subprocess environment propagation
packages/sdk/src/worker.ts, packages/sdk/src/worker-cli.ts, packages/sdk/src/local-agent.ts, packages/sdk/src/communication/*, packages/sdk/src/llm-worker.ts, packages/sdk/tests/communication-worker.test.ts, packages/sdk/tests/worker-cli.test.ts
Agent, communication, and LLM workers pass configured environments to provider subprocesses. Tests check credential forwarding and isolation from ambient variables.
Cloud artifact capability validation
scripts/cloud-artifact.mjs, scripts/cloud-artifact.test.mjs
Artifact manifests declare local-agent-env-fd-v1. Verification rejects manifests whose capability list does not match the supported values.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant CLI
  participant localAgentEnvironment
  participant AgentWorker
  participant runAgentCli
  participant ProviderCLI
  CLI->>localAgentEnvironment: Read and validate descriptor credentials
  localAgentEnvironment-->>CLI: Return credential overlay
  CLI->>AgentWorker: Attach with environment
  AgentWorker->>runAgentCli: Run with processEnvironment
  runAgentCli->>ProviderCLI: Spawn with supplied environment
Loading

Suggested reviewers: miyaontherelay, kjgbot

Merge Risk: ⚪ Minimal · up to 27a01

The credential handoff and environment forwarding are consistent with the isolation objective, and artifact verification requires the matching runtime capability. No concrete merge-blocking issue remains; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 27a01

The handoff reduces credential exposure through the flow’s environment, but readiness checks can still pass those credentials to flow-selected executables. Production exposure depends on host-side executable and credential controls that remain unverified.

Retained concerns

  • Medium · security · inferred: The new handoff forwards descriptor-only provider credentials into probes whose executable can be selected by authored code or project configuration. Unmanaged identification probes receive the full composed environment before executable trust is established, allowing a flow-owned executable to obtain handed-off keys. The older ambient-environment behavior predates this PR; production exploitability of the new credential path depends on host controls that remain unverified.
Security review details

Security Blast Radius

  • inferred — A selected probe executable can access the provider credentials supplied to that invocation. Those credentials may authorize provider-account use or disclosure; tenant count, account privileges, and cross-service or cross-environment reach cannot be determined without the creator-side authorization policy.

Security Findings and Attack Paths

  • inferred — A conditional attack path is authored cli selection to executable resolution, then an identification probe carrying descriptor-derived credentials. Resolution checks executability, not trusted ownership, and identification results arrive only after the credential-bearing process starts. This is a source-supported design concern, not a verified production exploit.

Trust Boundaries and Controls

  • observed — Managed probes clear inherited environment values and select provider-specific credentials; managed wrapper probes can return without identification. These controls narrow exposure but do not apply to unmanaged probes, and provider selection is based on the executable basename rather than authenticated executable identity.

Resilience and Maintainability Implications

  • observed — Default production callers consume the handoff before authored imports, and malformed payloads fail before evaluation. The tests cover local descriptor merging, closure, marker removal, and selected validation failures using regular files; they do not establish production creator authorization or stalled-pipe recovery.

Hardening Proposals

  • proposed — Bind credential-bearing probes to host-approved executable identities, keeping identification of authored or project-owned programs credential-free. Define the handoff creator’s per-run credential authority, finite writer lifecycle, and capability-gated rollback behavior.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 23.53% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 34 functions across 24 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: isolating local agent credentials from authored code.
Description check ✅ Passed The description directly explains credential isolation, descriptor handling, subprocess propagation, validation, and test results for this changeset.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the keys with care
Then sends them where the workers fare
The probes receive the chosen air
The child flows keep credentials fair
Cloud manifests record the share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T17:49:42.145025Z 27a0115 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 4 potential issues.

2 flags not posted on this PR by your GitHub settings — view them in Devin Review. (Configure)

Devin Review

Comment thread packages/sdk/src/cli/run.ts
Comment thread packages/sdk/src/cli/direct-run.ts
Comment thread packages/sdk/src/local-agent-environment.ts
Comment thread packages/sdk/src/local-agent-environment.ts

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 77bc039. Configure here.

Comment thread packages/sdk/src/cli/run.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 77bc0393e7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/sdk/src/cli/run.ts Outdated
Comment thread packages/sdk/src/worker.ts
Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
@khaliqgant

Copy link
Copy Markdown
Member Author

@codex review

Please re-review the current head e8fb83f after the fixes for all existing findings.

Session-Id: 01a0e3a9-9c75-76f1-9425-fcd47b8a081e
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: e8fb83f59a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@khaliqgant

Copy link
Copy Markdown
Member Author

@codex review

Final head 27a0115 adds only the authenticated runtime capability marker and its contract test. Please review this exact head.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 27a0115cb9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@khaliqgant
khaliqgant merged commit 5b9cb46 into main Sep 30, 2026
9 checks passed
@khaliqgant
khaliqgant deleted the fix/house-authored-credential-isolation branch September 30, 2026 17:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant