docs: record the guardrail gaps that are accepted on purpose #111

Merged
alee merged 1 commits from feat/agent-guardrails into main 2026-10-05 01:34:53 +00:00
Owner

What

Docs only: one commit (a0362d3) that landed on feat/agent-guardrails after #110 was merged.

  • Adds a Known gaps section to docs/agent-guardrails.md.
  • Tightens the bash_protected_port row: what it matches and why 8080 is protected.

No code changes. The plugin, scripts and tests are untouched.

Why

A live check on 2026-10-04 showed the agent's blocked curl localhost:8080/health succeeding when retried through webfetch. The decision was to accept that gap rather than add a rule, and to write it down. Each gap below was probed at the hook boundary before it was documented.

  • The plugin inspects only task, call_omo_agent, edit, write and bash, so webfetch of localhost:8080 passes.
  • bash_protected_port matches literal localhost / 127.0.0.1 / 0.0.0.0 plus :8080. It misses [::1]:8080, the machine's own address and URLs held in variables, and it blocks a commit message that names localhost:8080. It does see inside bash -c and python3 -c.
  • bash -c '...' / sh -c '...' wrappers evade bash_banned and bash_main_checkout: bash -c 'pkill -f foo' and bash -c 'git stash' both pass.
  • bash_main_checkout can mis-anchor a relative cd chain that follows an absolute one.

Verification

Docs only; no test reads the file. The probes are the evidence: each claim in the new section was run through the real hook (tool.execute.before with {tool, sessionID, callID} and {args}) and the allow/block result recorded.

🤖 Generated with Claude Code

https://claude.ai/code/session_01KkCGRantZsSwmcFpet6FTa

## What Docs only: one commit (`a0362d3`) that landed on `feat/agent-guardrails` after #110 was merged. - Adds a **Known gaps** section to `docs/agent-guardrails.md`. - Tightens the `bash_protected_port` row: what it matches and why 8080 is protected. No code changes. The plugin, scripts and tests are untouched. ## Why A live check on 2026-10-04 showed the agent's blocked `curl localhost:8080/health` succeeding when retried through `webfetch`. The decision was to accept that gap rather than add a rule, and to write it down. Each gap below was probed at the hook boundary before it was documented. - The plugin inspects only `task`, `call_omo_agent`, `edit`, `write` and `bash`, so `webfetch` of `localhost:8080` passes. - `bash_protected_port` matches literal `localhost` / `127.0.0.1` / `0.0.0.0` plus `:8080`. It misses `[::1]:8080`, the machine's own address and URLs held in variables, and it blocks a commit message that names `localhost:8080`. It does see inside `bash -c` and `python3 -c`. - `bash -c '...'` / `sh -c '...'` wrappers evade `bash_banned` and `bash_main_checkout`: `bash -c 'pkill -f foo'` and `bash -c 'git stash'` both pass. - `bash_main_checkout` can mis-anchor a relative `cd` chain that follows an absolute one. ## Verification Docs only; no test reads the file. The probes are the evidence: each claim in the new section was run through the real hook (`tool.execute.before` with `{tool, sessionID, callID}` and `{args}`) and the allow/block result recorded. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01KkCGRantZsSwmcFpet6FTa
alee added 1 commit 2026-10-05 01:34:22 +00:00
Add a Known gaps section to docs/agent-guardrails.md and tighten the
bash_protected_port row. Each gap was probed at the hook boundary:

- the plugin inspects only task, call_omo_agent, edit, write and bash, so
  webfetch of localhost:8080 passes (seen live 2026-10-04)
- bash_protected_port matches literal host:port text, so [::1], the
  machine address and URLs held in variables are missed
- bash -c / sh -c wrappers evade bash_banned and bash_main_checkout
  (the port rule still sees inside them)
- a relative cd chain after an absolute one can be mis-anchored

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KkCGRantZsSwmcFpet6FTa
alee merged commit 5f51d772a3 into main 2026-10-05 01:34:53 +00:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: alee/6krrt#111