Skip to content

agent: config-file credentials and read_log output still reach the model after #3041 — mask credential values in agent reads #3097

Description

@DavidCockerill

Summary

#3041 narrows the built-in agent's config filesystem scope to the config file, and makes the fs tools refuse key material (key directories, *.pem/*.key/.jwtPass, PEM private-key text) in every scope. Two read paths still return credential values to the model, and from there they go into the session transcript, which is persisted, audited and replicated with the system database:

  1. The config file's own values. read_file(root:'config', path:'harper-config.yaml') returns the file whole. That includes plaintext credentials such as models.<kind>.<name>.apiKey: a key supplied through HARPER_SET_CONFIG is written into the file. get_configuration returns the same values, and it is kept off the agent's default operations allow-list for exactly that reason (components/mcp/tools/operations.ts, DEFAULT_ALLOW); the fs read reaches the same bytes.
  2. read_log. It is on the default allow-list and returns log text unfiltered. tail_file on the same log refuses PEM private-key text after agent: the read-only config filesystem scope is the whole Harper root — keys/ and database/ are readable; add agent.configScope and deny key material #3041, but read_log does not, and neither filters other credentials a component or error message might log.

Current behavior

Checked on david/agent-config-scope (the #3041 branch) with a dist-booted Harper driven by a fake model. With models.generative.default.apiKey supplied through HARPER_SET_CONFIG, the key is persisted in harper-config.yaml, and read_file(root:'config', path:'harper-config.yaml') returns it. apiKey: ${OPENAI_API_KEY} is supported (resources/models/bootstrap.ts), and then the file holds only the reference, but plaintext is the path HARPER_SET_CONFIG takes.

Proposal

Acceptance

  • read_file, grep_files and tail_file on the config file return apiKey: [redacted] for a plaintext key, and apiKey: ${OPENAI_API_KEY} unchanged.
  • read_log through the agent masks the same keys and refuses PEM private-key text.
  • Non-credential config values are returned unchanged.

Related

🤖 Generated by Claude Opus 5.5 (Claude Code); posted via @DavidCockerill.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

Fields

Priority

P2

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions