You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Let preview_type type a request_secret secretRef, so agents can sign in without seeing the password
#17290
An agent can't sign in to a site in a T3 browser tab without seeing the password. preview_type takes only literal text, so the value passes through the model and the tool call. Once it's in the page, preview_evaluate can also read it back from .value. We've seen an agent do exactly that.
Since #15328, an environment's tabs run in the server's own Chromium. That makes the gap harder to work around on a remote host. Anything that fills a field through the desktop app's local webview, including the Electron-main design in #7346, can't reach a tab that runs on the server.
Idea
request_secret already produces a one-use secretRef. It's bound to the project, expires after 24 hours, and the server consumes it without the value reaching the transcript or the model. Today only schedule_task's webhook signature accepts one. Let preview_type accept it too, in place of text:
The server consumes the ref and types the value the same way it types text. The result says only that the field was filled.
Server browser tabs could come first. There, the secret store and the browser live in the same server process, so the value never crosses an RPC contract, a client, or a desktop host. Desktop tabs could follow later, or refuse with a clear error until then.
The value stays in the page after filling. Either fill and submit in one step, or refuse preview_evaluate and recording on that tab until it navigates away or the field is cleared.
Bind the ref to an origin.request_secret could take an optional origin, so the card says where the value will be typed. preview_type would then refuse if the tab's top-level origin differs at fill time. That stops a prompt-injected agent from typing the user's password into another site.
Never echo the value. Keep it out of tool results, errors, logs, traces, and action history.
Why this shape
It reuses what already exists: secretRef, SecretRequests.consume, and the server browser's typing path.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Problem
An agent can't sign in to a site in a T3 browser tab without seeing the password.
preview_typetakes only literaltext, so the value passes through the model and the tool call. Once it's in the page,preview_evaluatecan also read it back from.value. We've seen an agent do exactly that.Since #15328, an environment's tabs run in the server's own Chromium. That makes the gap harder to work around on a remote host. Anything that fills a field through the desktop app's local webview, including the Electron-main design in #7346, can't reach a tab that runs on the server.
Idea
request_secretalready produces a one-usesecretRef. It's bound to the project, expires after 24 hours, and the server consumes it without the value reaching the transcript or the model. Today onlyschedule_task's webhook signature accepts one. Letpreview_typeaccept it too, in place oftext:The server consumes the ref and types the value the same way it types
text. The result says only that the field was filled.Server browser tabs could come first. There, the secret store and the browser live in the same server process, so the value never crosses an RPC contract, a client, or a desktop host. Desktop tabs could follow later, or refuse with a clear error until then.
Guards it probably needs
These follow #7346's prototype findings:
preview_evaluateand recording on that tab until it navigates away or the field is cleared.request_secretcould take an optionalorigin, so the card says where the value will be typed.preview_typewould then refuse if the tab's top-level origin differs at fill time. That stops a prompt-injected agent from typing the user's password into another site.Why this shape
secretRef,SecretRequests.consume, and the server browser's typing path.preview_typewouldn't need to change again.secretRefin shell commands.Limits
Questions
All reactions