提交前确认 · Pre-submission checklist
问题类别 · Category
对话 / Agent 交互 · Agent chat
涉及的 Agent 框架 · Agent framework
ZCode Agent(自研)
严重程度 · Severity
阻塞使用 · Blocking (无法使用核心功能 / core function unusable)
复现频率 · Reproducibility
必现 · Always
问题描述 · Description
经 CPA 网关调用 devin 系列模型时,ZCode 的所有子 agent 调用(Agent/Task
工具,全部类型)一律被上游内容风控拦截,返回 403 permission_denied。
影响面:主会话正常;拦截命中所有 devin/* 模型路由(不止 swe-2),而同一
system prompt 走 codex/antigravity 上游则正常 —— 说明拦截发生在 Devin
侧的内容风控层而非模型本身。已在服务器侧用原始请求对 CPA 复现,排除
网关/网络/配置因素。
已二分定位到具体语句:子 agent system prompt 的 Notes 段中有一行硬编码
字符串
- For clear communication with the user the assistant MUST avoid using emojis.
该行字面文本命中 Devin 上游的风控签名。实测仅把这一行改为以下任一版本,
整段请求即稳定通过(2/2):
- For clear communication with the user the assistant MUST avoid using emoticons.
- For clear communication with the user the assistant should not use emojis.
插入零宽字符 \u200b 无效(上游先做 Unicode 规范化再匹配)。
该模板在本机的位置(Linux,GLM agent bundle v0.13.3):
~/.zcode/server/agents/glm/zcode.cjs:函数 pSo() 返回 Notes 字符串
数组,被 Subagent Environment prompt 组装块调用 —— 因此只有子代理
请求中招,主会话 prompt 不含此段。
/opt/ZCode/resources/glm/zcode.cjs(安装源,bundle 更新时会同步回来)。
- browser-use 插件 bundle 内嵌同一 Notes 段(cache 与 resources 各一处)。
resources/app.asar 中不含该字符串(已 grep 确认)。
复现步骤 · Steps to reproduce
- ZCode 走 CPA 网关、会话模型选任一 devin/* 模型(如 devin/swe-2)
- 任意会话中发起一次子 agent 调用(prompt 任意,例如 "Reply with: ok")
- 立即返回 devin upstream error (permission_denied),模型侧未执行;
同一操作换 codex/antigravity 上游则正常
期望表现 · Expected behavior
子 agent 正常创建并返回结果;system prompt 不应因固定措辞被上游风控拦截。
实际表现 · Actual behavior
所有子 agent 调用返回:
devin upstream error (permission_denied): Your request was blocked by our
content policy. Please remove sensitive or unsafe content from your prompt,
memories, and other settings and try again.
ZCode 版本 · ZCode version
ZCode 3.14.3.7762
设备 / 系统 / 浏览器 · Device / OS / Browser
ThinkPad / windows 11
截图 / 录屏 / 日志 · Screenshots / Recordings / Logs
-
拦截响应(任意子 agent 调用均返回,含 trace ID):
devin upstream error (permission_denied): Your request was blocked by our
content policy. ... (trace ID: af0d3db13f7adb18f50628d3ad33a20d)
-
二分定位:仅将 "MUST avoid using emojis" 改为 "should not use emojis" /
"emoticons",同一请求稳定通过(HTTP 200,无 event: error);插入 \u200b
仍被拦(规范化后被还原)。受影响面覆盖全部 devin/* 路由,不止 swe-2。
-
本地临时修复(已验证):对 ~/.zcode/server/agents/glm/zcode.cjs 执行
sed 's/MUST avoid using emojis/should not use emojis/' 并重启 ZCode 后,
子 agent 调用全部恢复正常,node --check 通过。
建议修复:上游模板将该句改写为不命中风控签名的等价表述(emoji 限制语义
保留),并同步修正各 bundle/插件中的副本。
提交前确认 · Pre-submission checklist
问题类别 · Category
对话 / Agent 交互 · Agent chat
涉及的 Agent 框架 · Agent framework
ZCode Agent(自研)
严重程度 · Severity
阻塞使用 · Blocking (无法使用核心功能 / core function unusable)
复现频率 · Reproducibility
必现 · Always
问题描述 · Description
经 CPA 网关调用 devin 系列模型时,ZCode 的所有子 agent 调用(Agent/Task
工具,全部类型)一律被上游内容风控拦截,返回 403 permission_denied。
影响面:主会话正常;拦截命中所有 devin/* 模型路由(不止 swe-2),而同一
system prompt 走 codex/antigravity 上游则正常 —— 说明拦截发生在 Devin
侧的内容风控层而非模型本身。已在服务器侧用原始请求对 CPA 复现,排除
网关/网络/配置因素。
已二分定位到具体语句:子 agent system prompt 的 Notes 段中有一行硬编码
字符串
该行字面文本命中 Devin 上游的风控签名。实测仅把这一行改为以下任一版本,
整段请求即稳定通过(2/2):
插入零宽字符 \u200b 无效(上游先做 Unicode 规范化再匹配)。
该模板在本机的位置(Linux,GLM agent bundle v0.13.3):
~/.zcode/server/agents/glm/zcode.cjs:函数pSo()返回 Notes 字符串数组,被
Subagent Environmentprompt 组装块调用 —— 因此只有子代理请求中招,主会话 prompt 不含此段。
/opt/ZCode/resources/glm/zcode.cjs(安装源,bundle 更新时会同步回来)。resources/app.asar中不含该字符串(已 grep 确认)。复现步骤 · Steps to reproduce
同一操作换 codex/antigravity 上游则正常
期望表现 · Expected behavior
子 agent 正常创建并返回结果;system prompt 不应因固定措辞被上游风控拦截。
实际表现 · Actual behavior
所有子 agent 调用返回:
devin upstream error (permission_denied): Your request was blocked by our
content policy. Please remove sensitive or unsafe content from your prompt,
memories, and other settings and try again.
ZCode 版本 · ZCode version
ZCode 3.14.3.7762
设备 / 系统 / 浏览器 · Device / OS / Browser
ThinkPad / windows 11
截图 / 录屏 / 日志 · Screenshots / Recordings / Logs
拦截响应(任意子 agent 调用均返回,含 trace ID):
devin upstream error (permission_denied): Your request was blocked by our
content policy. ... (trace ID: af0d3db13f7adb18f50628d3ad33a20d)
二分定位:仅将 "MUST avoid using emojis" 改为 "should not use emojis" /
"emoticons",同一请求稳定通过(HTTP 200,无 event: error);插入 \u200b
仍被拦(规范化后被还原)。受影响面覆盖全部 devin/* 路由,不止 swe-2。
本地临时修复(已验证):对 ~/.zcode/server/agents/glm/zcode.cjs 执行
sed 's/MUST avoid using emojis/should not use emojis/' 并重启 ZCode 后,
子 agent 调用全部恢复正常,node --check 通过。
建议修复:上游模板将该句改写为不命中风控签名的等价表述(emoji 限制语义
保留),并同步修正各 bundle/插件中的副本。