Skip to content

fix: tighten privacy-safe cloud reporting - #136

Merged
Mr-Lucky merged 1 commit into
mainfrom
fix/privacy-safe-cloud-reporting
Sep 29, 2026
Merged

Mr-Lucky merged 1 commit into
mainfrom
fix/privacy-safe-cloud-reporting

Conversation

@Mr-Lucky

Copy link
Copy Markdown
Contributor

Summary

  • Keep routine model requests and all model responses out of Cloud event ingest.
  • Preserve bounded protected-file summaries such as cat .env and cat .ssh/id_ed25519.pub.
  • Continue suppressing absolute paths, usernames, command tails, sensitive arguments, and unsafe filenames.
  • Add regression tests and update privacy-boundary documentation.

Type

  • Bug fix
  • New feature / detection rule
  • Refactoring
  • Documentation

Testing

  • npm run build passes
  • npm test passes (859 tests)
  • Manually tested the change

Related Issues

Closes #

@github-actions

Copy link
Copy Markdown

AgentGuard PR Review

  1. severity: high — src/runtime/audit.ts / shouldReportAuditEventToCloud() and src/cloud/client.ts ingest filtering

    • What can go wrong: The new Cloud gate only allows llm_request events when privacySummary has a PII category and the action was not blocked. This means any non-PII model request that still contains sensitive prompt material, secrets, or regulated data will now be silently dropped from Cloud ingest even though the docs still describe “redacted request observations” being uploadable. That is a correctness regression in the Cloud telemetry pipeline and can break downstream detection/monitoring that expects routine model-request records.
    • Fix suggestion: Keep the existing Cloud upload path for all redacted model-request records, and add a separate flag/field for “PII egress confirmed” rather than suppressing all non-PII model requests. If requests must be filtered, make the policy explicit in the event schema and update all producers/consumers consistently.
  2. severity: medium — src/runtime/audit.ts nativeHookAuditInput() / safeGenericProtectedTarget() and the added tests

    • What can go wrong: The new “protected-file summary” extraction can still leak the command tail or non-file arguments for some shell forms because the parser is heuristic and only splits on ;&|. Shell syntax like cat /tmp/.env $(curl ...), subshells, redirects, or cat -- /private/workspace/.env can produce a summarized input that is not actually bounded to the file access or may misidentify the target. This is security-sensitive because the patch’s goal is to preserve only a minimal file summary.
    • Fix suggestion: Restrict preservation to a strict allowlist of fully parsed command shapes, or emit the safe summary only from the already-validated policy/evaluator context (e.g. the approved target path) instead of re-parsing raw shell text. Add tests for redirects, subshells, --, and multi-command cases to ensure tails are never retained.

@Mr-Lucky
Mr-Lucky merged commit ba2ac38 into main Sep 29, 2026
4 checks passed
@Mr-Lucky
Mr-Lucky deleted the fix/privacy-safe-cloud-reporting branch September 29, 2026 07:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant