Repository navigation
Let agents hand tasks to agents that can read raw secrets; such a task runs fill-only - #53
Merged
Merged
Conversation
…k runs fill-only
Godmode could not delegate to an agent with reveal access ("Target agent can reveal secrets; only the human can
hand it tasks from here"), so work for such an agent always needed the human. agent_delegate now goes through for
every caller. Unless the caller's run reads raw secrets itself and the target is global or in its workspace, the
task's chat is marked fill-only (conversations.secret_access, migration 31): vault_get_login / vault_get_totp are
off in it for good, the prompt says so, and logins and 2FA codes are still filled into pages. Delegating across
workspaces to a reveal-mode agent works the same way.
In a fill-only chat a reveal-mode agent counts as fill-only for what it hands on or sets up, itself included:
automations, assigning board tasks, agent settings and giving an agent a VM are refused as they are for a
fill-only caller. A chat that is gone counts as fill-only. Those refusals are otherwise unchanged, as is the rule
for agents that control the computer on their own.
The migration id leaves a gap on purpose: several branches are open, and a second migration with the same id
would be skipped without a word.
# Conflicts: # docs/ARCHITECTURE.md # packages/core/src/db/migrations.ts # packages/core/src/mcp/tools.ts # packages/core/src/runner/prompt.ts # packages/core/src/runner/runner.ts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Godmode could not hand a task to an agent with reveal access. The call failed with "Target agent can reveal secrets; only the human can hand it tasks from here.", so every task for such an agent (here: a lead research batch for the Lead Researcher) needed the human.
What you get
vault_get_login/vault_get_totpare off in the task's chat — for the task and for everything that happens in that chat later. Logins and 2FA codes are still filled into pages.Still only for the human
For a reveal-mode agent, a caller that reads no raw secrets still cannot change its settings or instructions, create or change its automations, assign it board tasks or give it a VM. These outlive a single task, so running the task fill-only does not cover them.
agent_updatefor such an agent is refused as before.How it works
agent_delegateno longer calls the reveal refusal. It creates the task's chat withsecret_access = 'fill'(new column onconversations, migration 31) when the caller's run could not read raw secrets for that target.Migration id 31 leaves a gap on purpose: several branches are open, and a second migration with the same id would be skipped silently.
Risks
MEMORY.mdand repository; a later run of that agent with raw-secret access may act on text planted there. This comes with allowing the hand-over at all — the old refusal was the only thing that prevented it.SECURITY.mdsays so.main, not changed here:task_updatelets a fill-only manager edit the title or description of a board task that is assigned to a reveal-mode agent;vm_assignto a workspace has no reveal check; login allow-lists are not compared when deciding whether a delegated chat keeps raw secrets.Checked
bun testinpackages/core: 939 pass, 10 skipped, 0 fail.pnpm typecheckclean.test/mcp.test.ts: the hand-over from a fill-only delegator and a fill-only manager, the tools and the prompt in that chat (also for a later message in it), the chain, the refusals inside a fill-only chat (own agent included), a chat that is gone, and that the agent still reads raw secrets in a chat of its own.agent_delegatesucceeded, the Lead Researcher wroteworkspace/leads/smoke.csvand its answer came back; the delegated chat was marked fill-only, the agent reported no raw-secret tools, and no reveal was audited.Not verified