fix(agents): address all PR #2299 code review findings
Blocking fixes: - B1: Return empty restrictions for unknown/custom agents instead of EXPLORATION_AGENT_DENYLIST, allowing custom agents full tool access - B2: Use Object.create(null) consistently across all 5 agent-loading result objects to prevent prototype pollution - B3: Add code comment documenting custom agent bash access trust model - B4: Mock getOpenCodeConfigDir in opencode-config-agents-reader tests to prevent global config dir leakage Non-blocking fixes: - N1: Use resolveAgentDefinitionPaths with project boundary enforcement in opencode-config-agents-reader for path containment - N2: Add session-scoped 30s TTL cache to resolveCallableAgents to avoid redundant SDK IPC calls per tool invocation - N3: Extract shared parseToolsConfig into src/shared/parse-tools-config.ts replacing 4 duplicated local implementations - N4: Add .min(1) to AgentDefinitionPathSchema rejecting empty paths - N5: Add resolve-agent-definition-paths.test.ts covering tilde expansion, relative paths, boundary enforcement, and null containmentDir - N6: Validate agent mode against allowed values instead of bare type assertion in opencode-config-agents-reader
This commit is contained in:
@@ -2,23 +2,11 @@ import { existsSync, readFileSync } from "fs"
|
||||
import { basename, extname } from "path"
|
||||
import { parseFrontmatter } from "../../shared/frontmatter"
|
||||
import { log } from "../../shared/logger"
|
||||
import { parseToolsConfig } from "../../shared/parse-tools-config"
|
||||
import { parseJsonAgentFile } from "./json-agent-loader"
|
||||
import { mapClaudeModelToOpenCode } from "./claude-model-mapper"
|
||||
import type { AgentScope, AgentFrontmatter, ClaudeCodeAgentConfig, LoadedAgent } from "./types"
|
||||
|
||||
function parseToolsConfig(toolsStr?: string): Record<string, boolean> | undefined {
|
||||
if (!toolsStr) return undefined
|
||||
|
||||
const tools = toolsStr.split(",").map((t) => t.trim()).filter(Boolean)
|
||||
if (tools.length === 0) return undefined
|
||||
|
||||
const result: Record<string, boolean> = {}
|
||||
for (const tool of tools) {
|
||||
result[tool.toLowerCase()] = true
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
export function parseMarkdownAgentFile(filePath: string, scope: AgentScope): LoadedAgent | null {
|
||||
try {
|
||||
if (!existsSync(filePath)) {
|
||||
@@ -67,7 +55,7 @@ export function loadAgentDefinitions(
|
||||
paths: string[],
|
||||
scope: AgentScope
|
||||
): Record<string, ClaudeCodeAgentConfig> {
|
||||
const result: Record<string, ClaudeCodeAgentConfig> = {}
|
||||
const result: Record<string, ClaudeCodeAgentConfig> = Object.create(null)
|
||||
|
||||
for (const filePath of paths) {
|
||||
if (!existsSync(filePath)) {
|
||||
|
||||
Reference in New Issue
Block a user