open-swe/agent/webhooks
Adam Moussa ea1845d41d
fix(security): fence and neutralize untrusted Slack channel description in agent prompt
Hardens SLACK-PI-001 (sh-security-review). Slack channel topic/purpose is
editable by ordinary channel members and flowed verbatim into the agent LLM
prompt behind only a prose 'untrusted' label — an indirect prompt-injection
vector for an agent with network egress and repo write. Now strip leading
markdown structural tokens per line (so it can't forge the prompt's real
request/section delimiters), cap length, and wrap it in a per-render
unguessable sentinel fence (so injected text can't spoof a closing marker to
escape the data block). Deliberately diverges from upstream #1633.
2026-07-03 16:08:35 -04:00
..
__init__.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
github.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
linear.py refactor: adopt modular webhook architecture (#1621) + port fork customizations (#85) 2026-06-30 18:46:46 -04:00
slack.py fix(security): fence and neutralize untrusted Slack channel description in agent prompt 2026-07-03 16:08:35 -04:00