Confirmed outbound redaction gap
Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P1.
Default numbered read_file returns recognized credential-shaped source content without the secret scrub applied by raw mode and ordinary tool delivery. deliver_output exempts all read_file output; only the raw branch scrubs before return.
Synthetic-only reproduction
Create a disposable config containing an invented password-shaped assignment. Call the production executor's numbered and raw read_file paths. Inspect presence with boolean comparisons, never print the fixture value.
numbered_ok=True
numbered_contains_fixture=True
numbered_equals_self_scrubbed=False
raw_ok=True
raw_contains_fixture=False
raw_content_redacted=True
trajectory_copy_contains_fixture=True
agent_result_contains_fixture=False
audit_capped_contains_fixture=False
Independently reproduced by three reviewers; no real credentials were accessed.
Confirmed impact and limits
- The foreground Discord tool loop puts the unsanitized numbered output into model-facing tool-result content.
- Trajectory copying preserves it, and enabled turn-state persistence has a source-traced path storing capped result/transcript content without another blanket result scrub.
- These persistence claims are conditional on enabled features and content caps, not claims of observed live exposure.
- The normal agent result path and audit logger scrub independently. Do not claim those stores leak this fixture.
Source consumers: foreground result handling, trajectory copying, durable result write.
Acceptance criteria
- Scrub numbered reads before model-facing delivery, preserving whole-line numbering, ranges and continuation metadata.
- Preserve raw framing, byte count and
content_redacted semantics.
- Add boolean-only synthetic-secret tests for default executor output and foreground result/persistence handling.
- Do not introduce path restrictions or remove authorized file-reading capability; this is the existing secret-output contract.
Behavior change: recognized credential assignments are masked in numbered mode as intended. No source changes were made. A scout's separate claim about the existing redaction test fixture was rejected as display-scrubbing confusion and is not part of this issue.
Confirmed outbound redaction gap
Reviewed
masterat886c36d8ebe861aa987059a1744d45b78797baae(v4.7.0). Suggested priority: P1.Default numbered
read_filereturns recognized credential-shaped source content without the secret scrub applied by raw mode and ordinary tool delivery.deliver_outputexempts allread_fileoutput; only the raw branch scrubs before return.Synthetic-only reproduction
Create a disposable config containing an invented password-shaped assignment. Call the production executor's numbered and raw
read_filepaths. Inspect presence with boolean comparisons, never print the fixture value.Independently reproduced by three reviewers; no real credentials were accessed.
Confirmed impact and limits
Source consumers: foreground result handling, trajectory copying, durable result write.
Acceptance criteria
content_redactedsemantics.Behavior change: recognized credential assignments are masked in numbered mode as intended. No source changes were made. A scout's separate claim about the existing redaction test fixture was rejected as display-scrubbing confusion and is not part of this issue.