Skip to content

Fix secret tripwire fail-closed bypasses#2

Draft
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-5e1f
Draft

Fix secret tripwire fail-closed bypasses#2
cursor[bot] wants to merge 1 commit into
mainfrom
cursor/critical-bug-management-5e1f

Conversation

@cursor

@cursor cursor Bot commented Jun 17, 2026

Copy link
Copy Markdown

Summary

  • scan and fail-closed redact secrets nested inside structured OpenClaw tool inputs
  • keep vendored secret rules when fetched manifests contain no rules
  • preserve and re-scan original text when Node/OpenClaw tokenization responses omit tokenized_text

Validation

  • npm test in openclaw-plugin
  • npm run build in openclaw-plugin
  • npm test in node
  • PYTHONPATH=src python3 -m pytest tests/test_secret_tripwire.py tests/test_secret_tripwire_wiring.py in python
Open in Web View Automation 

Co-authored-by: Joshua Ferguson <JoshuaAFerguson@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant