Skip to content

Numbered read_file bypasses secret scrubbing before foreground model delivery #393

Description

@Calmingstorm

Confirmed outbound redaction gap

Reviewed master at 886c36d8ebe861aa987059a1744d45b78797baae (v4.7.0). Suggested priority: P1.

Default numbered read_file returns recognized credential-shaped source content without the secret scrub applied by raw mode and ordinary tool delivery. deliver_output exempts all read_file output; only the raw branch scrubs before return.

Synthetic-only reproduction

Create a disposable config containing an invented password-shaped assignment. Call the production executor's numbered and raw read_file paths. Inspect presence with boolean comparisons, never print the fixture value.

numbered_ok=True
numbered_contains_fixture=True
numbered_equals_self_scrubbed=False
raw_ok=True
raw_contains_fixture=False
raw_content_redacted=True
trajectory_copy_contains_fixture=True
agent_result_contains_fixture=False
audit_capped_contains_fixture=False

Independently reproduced by three reviewers; no real credentials were accessed.

Confirmed impact and limits

  • The foreground Discord tool loop puts the unsanitized numbered output into model-facing tool-result content.
  • Trajectory copying preserves it, and enabled turn-state persistence has a source-traced path storing capped result/transcript content without another blanket result scrub.
  • These persistence claims are conditional on enabled features and content caps, not claims of observed live exposure.
  • The normal agent result path and audit logger scrub independently. Do not claim those stores leak this fixture.

Source consumers: foreground result handling, trajectory copying, durable result write.

Acceptance criteria

  • Scrub numbered reads before model-facing delivery, preserving whole-line numbering, ranges and continuation metadata.
  • Preserve raw framing, byte count and content_redacted semantics.
  • Add boolean-only synthetic-secret tests for default executor output and foreground result/persistence handling.
  • Do not introduce path restrictions or remove authorized file-reading capability; this is the existing secret-output contract.

Behavior change: recognized credential assignments are masked in numbered mode as intended. No source changes were made. A scout's separate claim about the existing redaction test fixture was rejected as display-scrubbing confusion and is not part of this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions