Repository navigation
File upload from the private artifact store #168
Description
Activity
- addedtype:featureNew capability or commandNew capability or commandtype:securitySecurity boundary or hardeningSecurity boundary or hardeningarea:core-protocolHeadlessProtocol: wire protocol, validation, transportHeadlessProtocol: wire protocol, validation, transportarea:macos-hostWKWebView host (main.swift, Host/)WKWebView host (main.swift, Host/)area:linux-hostChromium host (LinuxHost/, CDP)Chromium host (LinuxHost/, CDP)area:agent-runtimeInjected JS: inspection, pruning, refsInjected JS: inspection, pruning, refsarea:cliCLI parser, help, capabilitiesCLI parser, help, capabilitiespriority:mediumScheduled, not blockingScheduled, not blocking
on Sep 10, 2026 - added a commit that references this issue
on Sep 12, 2026 PR #169 delivered the safe half of this issue: an agent can attach a validated file that already exists in the private artifact store. It intentionally removed the proposed agent/MCP-facing
artifacts add <local-path>command because that surface would let an agent read and exfiltrate arbitrary host files with allowed extensions. Reopening this issue for the remaining trusted, user-mediated staging design. The completed upload command must remain restricted to private-store basenames.Shipped in #169. Agents can
uploada basename that already exists in the private artifact store. Ingest is a local CLI operator path (headless artifacts add), not a protocol or MCP command, so the agent cannot read arbitrary files. WebKit still returnsUNSUPPORTED_CAPABILITY.
What an agent cannot do today
Agents cannot attach a file to
<input type=file>. Inspect deliberately does not advertiseupload. QA of resume/import/image flows requires a human. Downloads stay denied; this is the inverse: a user-supplied fixture enters the private artifact store, then the host attaches it.Proposed surface
headless artifacts add ./resume.pdf --name resume.pdf headless artifacts list headless upload --role textbox --name "Resume" --artifact resume.pdf headless upload @e12 --artifact resume.pdfartifacts addcopies a local regular file into the existing0700artifact store as a new0600O_EXCLname.uploadtakes the same target grammar asclickand an artifact basename only. The password never leaves the store as a socket payload; the host uses the on-disk path.Engines
Both if the engine can attach a file without an arbitrary-JS verb.
DOM.setFileInputFileswith the artifact path.UNSUPPORTED_CAPABILITYand declarefileUploadfalse. Do not fake it with page JavaScript that the site could observe as a hole.Contract
Architecture-decision entry in the same PR. Downloads remain denied. No home-directory paths on
upload. No TCP fixture server.artifacts add:pdf,png,jpg,jpeg,gif,webp,txt,csv,json. Nothtml,svg,exe, archives, or the blocked download extensions.upload:<input type=file>(or equivalent file control). Anything else isELEMENT_NOT_FOUND/ invalid target, not a silent click.uploadon file inputs once the command exists. Update the protocol test that currently forbids that string.Tests
Protocol: parse, reject path traversal, reject
.exe/.html, reject overwrite, reject oversized add, rejectuploadwithout a stored artifact, reject upload to a non-file control.Linux E2E: add a tiny pdf/png fixture, upload into a file input, assert the page sees a filename. macOS E2E: same, or assert
UNSUPPORTED_CAPABILITYif WebKit cannot attach files.Docs
COMMANDS.md,agentHelp, skill, capabilitiesfileUpload, what-is-excellent note that upload is artifact-store only.