Repository navigation
fix(mcp): mark page text as untrusted in every agent tool answer - #302
Merged
Merged
Conversation
Several agent tools returned strings the inspected page controls without the untrusted-data notice the other tools already use, so a page could plant text that reads like instructions to the agent. Add untrusted() next to the shared UNTRUSTED notice in forms-tools.ts and put it in front of the answers of inspect-component (live property values), inspect-signals (signal values, kept inside the 20,000 character cap), inspect-providers (token names and route injectors), defer-blocks (page URL), explain-pipe (last input and output), dispatch-ngrx-action (page message and error), form-action and fill-form (page messages and skipped reasons), and the unknown page answer that lists page URLs. analog-call-api now uses the Analog notice before the response body, and list-http-calls keeps its notice when no call matches the filter. Answers with only ids, class names and tags (highlight), source scans and lint-pipes are left as they are. The security page lists every notice and the tools that use it.
🚀 Deploying Preview to Cloudflare 🚀Preview Deployments by commit
|
Contributor
Keep both sides: the inspect-component answer passes the notice as part of its heading to inspectComponentText, so the 20,000 character cap counts it, and defer-blocks puts the notice inside capped(). The inspect-signals peek path returns through the same wrapped answers, and the merged forms caps already start with the notice. Tests cover the notice staying first and inside the cap for a large component detail and a cut defer block list.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Some agent tools returned page-controlled text (signal values, component property values, injector token names, defer block page URLs, pipe inputs and outputs, NgRx dispatch messages, form action messages, the Analog API response body, page URLs in unknown-page answers) without the untrusted-data notice the other tools use. A page could plant text that reads like instructions to the agent.
This adds
untrusted()next to the sharedUNTRUSTEDnotice inrpc/forms-tools.ts(same wording) and puts it in front of those answers:inspect-component,inspect-signals(inside the 20,000 character cap),inspect-providers,defer-blocks,explain-pipe,dispatch-ngrx-action, the page messageform-actionandfill-formreturn after a write, and the unknown-page answer when it lists URLs.analog-call-apiuses the existing Analog notice, andlist-http-callskeeps its notice on the "none match" answer. Answers without page text (highlight, source scans,lint-pipes, "no data yet") are unchanged. The security page lists every notice and the tools that use it.How it was verified
untrusted-notice.test.ts(10 tests; 9 fail without the change) plus ananalog-call-apiassertionpnpm test:devtools(1517/1518 on a heavily loaded machine; thepage-highlighttiming test timed out in the full runs and passes alone, untouched by this change)pnpm test:panel(242/242)pnpm typecheckpnpm format:checkpnpm docs:buildpnpm commit:checkScreenshots
None attached.
Notes for reviewers
inspect-signalsanswers now start with the notice before the JSON, so the "Cut to fit" note shows the graph budget (about 19,890) and the whole answer stays within 20,000.inspect-component,defer-blocksandinspect-signalsare kept to the wrapping lines to limit conflicts with feat(forms): cap the size of forms agent tool answers #299, fix(components): cap inspect-component and defer-blocks answers #300 and fix(signals): read injector graphs for inspect-signals without switching the panel #296.analog-call-apiresponse body is not redacted; that is out of scope here.Summary by CodeRabbit