You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Follow-up to #229 (M7a), which enforces a registry item's permission manifest at install time only (a static check of the code, --allow with --yes, and the receipt <agent-dir>/lousho-registry.json).
Goal
Use the receipt to enforce the manifest when the agent loads and runs, so an installed item cannot do more than it declared even if its code hides it from the static check:
tools from an item with exec: true (or any item whose needsApproval is true) always require approval;
sandbox egress for the item's tools limited to its network hosts (hostPattern / the credential broker allow-list);
only the item's declared env variables passed through where the SDK controls the environment;
loadAgentDir notices files whose sha256 no longer matches the receipt and reports it (warn or lousho doctor finding), without refusing edits the owner made on purpose.
Notes
Receipt format (v1): { "v": 1, "items": { "<name>": { "type", "registry", "installedAt", "permissions", "files": [{ "path", "sha256" }] } } }, written by src/cli/addReceipt.ts.
Follow-up to #229 (M7a), which enforces a registry item's permission manifest at install time only (a static check of the code,
--allowwith--yes, and the receipt<agent-dir>/lousho-registry.json).Goal
Use the receipt to enforce the manifest when the agent loads and runs, so an installed item cannot do more than it declared even if its code hides it from the static check:
exec: true(or any item whoseneedsApprovalis true) always require approval;networkhosts (hostPattern/ the credential broker allow-list);envvariables passed through where the SDK controls the environment;loadAgentDirnotices files whose sha256 no longer matches the receipt and reports it (warn orlousho doctorfinding), without refusing edits the owner made on purpose.Notes
{ "v": 1, "items": { "<name>": { "type", "registry", "installedAt", "permissions", "files": [{ "path", "sha256" }] } } }, written bysrc/cli/addReceipt.ts.