Skip to content

feat(security): pre-action content firewall over MCP/web/RAG/file/stdout untrusted inputs (#10552) - #10758

Merged
mrveiss merged 7 commits into
Dev_new_guifrom
issue-10552
Jun 30, 2026
Merged

mrveiss merged 7 commits into
Dev_new_guifrom
issue-10552

Conversation

@mrveiss

@mrveiss mrveiss commented Jun 30, 2026

Copy link
Copy Markdown
Owner

Thinking Path

Agent-framework epic #10542: wire the existing PromptInjectionDetector over all untrusted inputs (security, highest-risk gap).

What Changed

New security/content_firewall.py — one shared firewall run at every untrusted-input choke point: parallel executor (stdout/file), MCP client (call_tool + read_resource), web_fetch extract_url, RAG context assembly. Risk policy (env-tunable QUARANTINE/BLOCK/ESCALATE thresholds); untrusted spans delimited as DATA with a system note; high-risk recorded in the trajectory.

Verification

12 tests pass (seeded-injection quarantine/block, escalate, benign no-false-positive, singleton reuse, provenance). Closes #10552.

Model Used

Claude Opus 4.8 (subagent).

…out untrusted inputs (#10552)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown
Contributor

✅ SSOT Configuration Compliance: Passing

🎉 No hardcoded values detected that have SSOT config equivalents!

@mrveiss
mrveiss merged commit 05477ff into Dev_new_gui Jun 30, 2026
25 of 26 checks passed
@mrveiss
mrveiss deleted the issue-10552 branch June 30, 2026 20:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant