* feat(#52): add agent_skills_security.trusted_global_roots allowlist Opt-in allowlist so a global: agent skill whose SKILL.md realpath resolves outside the default global skills base (e.g. ~/.claude/skills) is accepted when its real target lies under a user-declared trusted root. Default [] is byte-identical to prior behavior; the symlink-escape guard is preserved and simply re-applied against each declared root. - src/security.cts: loadTrustedGlobalRoots — tilde-expand (~ and ~/), reject project-relative and dangerously broad roots (filesystem/UNC root, homedir), realpath-canonicalize each root every run and drop non-existent ones. - src/init.cts: on base-check failure the guard consults the trusted roots (hoisted out of the loop); emits a stderr NOTE when a skill is accepted via a trusted root so the widened boundary is visible. - src/core.cts: thread agent_skills_security through loadConfig. - config-schema.manifest.json: allow the new key path. - docs/CONFIGURATION.md: document the option and its security model. - tests/agent-skills.test.cjs: unit + end-to-end CLI coverage (regression, feature, negative, broad-root hardening, stderr NOTE). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(#52): add changeset fragment for trusted_global_roots (#754) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
193 lines
6.3 KiB
JSON
193 lines
6.3 KiB
JSON
{
|
|
"_comment": "Canonical schema manifest for valid config key paths. This manifest is the single CJS source of truth for valid config keys; dynamicKeyPatterns source strings are recompiled to RegExp at runtime by config-schema.cjs. runtimeStateKeys mirrors RUNTIME_STATE_KEYS.",
|
|
"validKeys": [
|
|
"mode",
|
|
"granularity",
|
|
"parallelization",
|
|
"commit_docs",
|
|
"model_profile",
|
|
"search_gitignored",
|
|
"brave_search",
|
|
"firecrawl",
|
|
"exa_search",
|
|
"workflow.research",
|
|
"workflow.plan_check",
|
|
"workflow.verifier",
|
|
"workflow.nyquist_validation",
|
|
"workflow.ai_integration_phase",
|
|
"workflow.ui_phase",
|
|
"workflow.ui_safety_gate",
|
|
"workflow.auto_advance",
|
|
"workflow.node_repair",
|
|
"workflow.node_repair_budget",
|
|
"workflow.tdd_mode",
|
|
"workflow.human_verify_mode",
|
|
"workflow.text_mode",
|
|
"workflow.research_before_questions",
|
|
"workflow.discuss_mode",
|
|
"workflow.skip_discuss",
|
|
"workflow.auto_prune_state",
|
|
"workflow.use_worktrees",
|
|
"workflow.worktree_skip_hooks",
|
|
"workflow.code_review",
|
|
"workflow.code_review_depth",
|
|
"workflow.code_review_command",
|
|
"workflow.pattern_mapper",
|
|
"workflow.plan_bounce",
|
|
"workflow.plan_bounce_script",
|
|
"workflow.plan_bounce_passes",
|
|
"workflow.plan_chunked",
|
|
"workflow.plan_review_convergence",
|
|
"workflow.post_planning_gaps",
|
|
"workflow.security_enforcement",
|
|
"workflow.security_asvs_level",
|
|
"workflow.security_block_on",
|
|
"workflow.drift_threshold",
|
|
"workflow.drift_action",
|
|
"code_quality.fallow.enabled",
|
|
"code_quality.fallow.scope",
|
|
"code_quality.fallow.profile",
|
|
"code_quality.fallow.mcp",
|
|
"ship.pr_body_sections",
|
|
"git.branching_strategy",
|
|
"git.base_branch",
|
|
"git.create_tag",
|
|
"git.phase_branch_template",
|
|
"git.milestone_branch_template",
|
|
"git.quick_branch_template",
|
|
"planning.commit_docs",
|
|
"planning.search_gitignored",
|
|
"planning.sub_repos",
|
|
"review.ollama_host",
|
|
"review.lm_studio_host",
|
|
"review.llama_cpp_host",
|
|
"review.default_reviewers",
|
|
"review.max_prompt_tokens",
|
|
"review.max_prompt_tokens_per_reviewer",
|
|
"workflow.cross_ai_execution",
|
|
"workflow.cross_ai_command",
|
|
"workflow.cross_ai_timeout",
|
|
"workflow.subagent_timeout",
|
|
"executor.stall_detect_interval_minutes",
|
|
"executor.stall_threshold_minutes",
|
|
"workflow.inline_plan_threshold",
|
|
"hooks.context_warnings",
|
|
"hooks.workflow_guard",
|
|
"workflow.context_coverage_gate",
|
|
"statusline.show_last_command",
|
|
"statusline.context_position",
|
|
"workflow.ui_review",
|
|
"workflow.max_discuss_passes",
|
|
"features.thinking_partner",
|
|
"context",
|
|
"features.global_learnings",
|
|
"learnings.max_inject",
|
|
"project_code",
|
|
"phase_id_convention",
|
|
"phase_naming",
|
|
"manager.flags.discuss",
|
|
"manager.flags.plan",
|
|
"manager.flags.execute",
|
|
"response_language",
|
|
"context_window",
|
|
"intel.enabled",
|
|
"graphify.enabled",
|
|
"graphify.build_timeout",
|
|
"graphify.auto_update",
|
|
"claude_md_path",
|
|
"claude_md_assembly.mode",
|
|
"runtime",
|
|
"resolve_model_ids",
|
|
"effort.default",
|
|
"fast_mode.enabled",
|
|
"plan_review.source_grounding",
|
|
"plan_review.source_grounding_authority",
|
|
"model_policy.provider",
|
|
"model_policy.budget",
|
|
"model_policy.high",
|
|
"model_policy.medium",
|
|
"model_policy.low",
|
|
"agent_skills_security.trusted_global_roots"
|
|
],
|
|
"runtimeStateKeys": [
|
|
"workflow._auto_chain_active"
|
|
],
|
|
"dynamicKeyPatterns": [
|
|
{
|
|
"topLevel": "agent_skills",
|
|
"source": "^agent_skills\\.[a-zA-Z0-9_-]+$",
|
|
"description": "agent_skills.<agent-type>"
|
|
},
|
|
{
|
|
"topLevel": "review",
|
|
"source": "^review\\.models\\.[a-zA-Z0-9_-]+$",
|
|
"description": "review.models.<cli-name>"
|
|
},
|
|
{
|
|
"topLevel": "features",
|
|
"source": "^features\\.[a-zA-Z0-9_]+$",
|
|
"description": "features.<feature_name>"
|
|
},
|
|
{
|
|
"topLevel": "claude_md_assembly",
|
|
"source": "^claude_md_assembly\\.blocks\\.[a-zA-Z0-9_]+$",
|
|
"description": "claude_md_assembly.blocks.<section>"
|
|
},
|
|
{
|
|
"topLevel": "model_profile_overrides",
|
|
"source": "^model_profile_overrides\\.[a-zA-Z0-9_-]+\\.(opus|sonnet|haiku)$",
|
|
"description": "model_profile_overrides.<runtime>.<opus|sonnet|haiku>"
|
|
},
|
|
{
|
|
"topLevel": "models",
|
|
"source": "^models\\.(planning|discuss|research|execution|verification|completion)$",
|
|
"description": "models.<planning|discuss|research|execution|verification|completion>"
|
|
},
|
|
{
|
|
"topLevel": "granularities",
|
|
"source": "^granularities\\.(planning|discuss|research|execution|verification|completion)$",
|
|
"description": "granularities.<planning|discuss|research|execution|verification|completion>"
|
|
},
|
|
{
|
|
"topLevel": "dynamic_routing",
|
|
"source": "^dynamic_routing\\.(enabled|escalate_on_failure|max_escalations|tier_models\\.(light|standard|heavy))$",
|
|
"description": "dynamic_routing.<enabled|escalate_on_failure|max_escalations|tier_models.<light|standard|heavy>>"
|
|
},
|
|
{
|
|
"topLevel": "model_overrides",
|
|
"source": "^model_overrides\\.[a-zA-Z0-9_-]+$",
|
|
"description": "model_overrides.<agent-id>"
|
|
},
|
|
{
|
|
"topLevel": "effort",
|
|
"source": "^effort\\.routing_tier_defaults\\.(light|standard|heavy)$",
|
|
"description": "effort.routing_tier_defaults.<light|standard|heavy>"
|
|
},
|
|
{
|
|
"topLevel": "effort",
|
|
"source": "^effort\\.agent_overrides\\.[a-zA-Z0-9_-]+$",
|
|
"description": "effort.agent_overrides.<agent-id>"
|
|
},
|
|
{
|
|
"topLevel": "fast_mode",
|
|
"source": "^fast_mode\\.routing_tier_defaults\\.(light|standard|heavy)$",
|
|
"description": "fast_mode.routing_tier_defaults.<light|standard|heavy>"
|
|
},
|
|
{
|
|
"topLevel": "fast_mode",
|
|
"source": "^fast_mode\\.agent_overrides\\.[a-zA-Z0-9_-]+$",
|
|
"description": "fast_mode.agent_overrides.<agent-id>"
|
|
},
|
|
{
|
|
"topLevel": "review",
|
|
"source": "^review\\.max_prompt_tokens_per_reviewer\\.[a-zA-Z0-9_-]+$",
|
|
"description": "review.max_prompt_tokens_per_reviewer.<reviewer-slug>"
|
|
},
|
|
{
|
|
"topLevel": "model_policy",
|
|
"source": "^model_policy\\.runtime_tiers\\.[a-zA-Z0-9_-]+\\.(opus|sonnet|haiku)$",
|
|
"description": "model_policy.runtime_tiers.<runtime>.<opus|sonnet|haiku>"
|
|
}
|
|
]
|
|
}
|