boardx / boardx/workspacex

P0: pdf-create L0 派生 execute 错误触发 L2 审批

Open
#3,590 2 comments 0 reactions 0 assignees View on GitHub
p0
Dominant language
TypeScript
Stars
0
Forks
0
Avg merge
1h 7m
Merged PRs (30d)
969

Description

生产 cn.10(exact 30f62910551d2713c3cf82f6990f4e4b7d38abf0)真实浏览器验收中,外层 call_skill(pdf-create) 正确识别为 L0,但其返回脚本进入派生 execute 后被作为独立 L2 工具处理,+38.4s 短暂显示 chat-tool-permission-dialog。用户要求生成 PDF 不应出现审批门。\n\n验收:\n- pdf-create 当前版本被解析为 L0。\n- 仅由该 L0 skill 产生、并由受控 sandbox 执行的派生 execute 继承该调用的权限上下文,不显示 L2 审批。\n- 用户直接请求 execute 或来源/skill 不可验证时继续 fail-closed 为 L2。\n- 真实 PDF 路径仍生成文件,权限事件和 provenance 可审计。\n\n动态证据(不含秘密):thread thr-ad6f2c21-e60f-42c4-87bb-461e15ed2bc6;run c450dee7-2c91-4f5d-a8df-1cea921278ad;trace 显示 data-risk=L2、intent=调用工具 execute;最终产物 4,271,420 bytes,持久化下载为 application/pdf 且文件头 %PDF-.

Contributor guide

No contributing guide indexed for this repository

Research direction

Trace the permission-classification path from call_skill(pdf-create) through its derived execute in the controlled sandbox, including chat-tool-permission-dialog and the audit/provenance events. Reproduce the reported browser flow with the supplied thread, run, or trace evidence. Done means sandbox-derived execute inherits the L0 context without an L2 dialog, while direct or unverifiable execute remains fail-closed and PDF generation and auditing still work.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
authorization, backend-api-design, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.