Skip to content

Replace dynamic agent log entries with fixed phrases to prevent data leakage Description #58

Description

@shahabmohi

In lib/sandbox/agents/cursor.ts (e.g., lines 16, 21, 25 and elsewhere), dynamic values (redacted command, stdout, stderr) are passed into TaskLogger. Even with the redaction helper, any miss or partial redaction can leak sensitive data. The Gemini agent follows the same pattern (e.g., lib/sandbox/agents/gemini.ts:22, 281).

Required change:

  • Replace all TaskLogger calls that include dynamic command/output content with fixed, non-variable phrases (e.g., “Command executed”, “Agent produced output”, “Agent error occurred”).
  • Add tests (or a lint rule) to prevent reintroduction of dynamic content in user-facing logs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions