Repository navigation
plat 601
| Field | Value |
|---|---|
| State | fixed on main |
| Priority | P0 |
| Product | sandbox |
| Area | confinement |
| Summary | trigger_and_auto_notify runs model-written Python on the server host, outside the CLI sandbox and slot accounts |
Review 2026-10-06 (confirmed by reading the code): executeTriggerPython (agent_go/cmd/server/background_code_tools.go:236)
writes the model's Python to a temp file and runs exec.CommandContext(python3, "-I", script) as the server's own OS
user, with a stripped environment and the workspace as working directory. It does not use the Landlock/Seatbelt
confinement or the per-user slot accounts that coding CLIs and execute_shell_command use, and nothing limits how many
run at once (each may wait up to 24h). docs/core/background_code_auto_notification.md promises the same user,
workspace and permissions as the originating turn; the code does not enforce that. Available in Builder (Goals) and
writable Crew chats. Shipped 2026-09-23, so it is likely on deployed servers. On a multi-user server (Excellence) the
code can read other users' workspaces.
Run the trigger through the same sandboxed executor as execute_shell_command (folder guard, Landlock/Seatbelt, slot
account), cap concurrent triggers per user, or disable the tool on multi-user servers until it is. Live proof: a
trigger that tries to read /etc/passwd or another user's workspace on Excellence is refused.
Owner: "we should not even have it". It had no recorded use locally (no auto-notify- executions in the logs or
chats); completion notices already resume a chat when a step, run, background agent or function call finishes, and Code
and Crew have durable one-time schedules for "check back later". trigger_and_auto_notify, its prompt section, its
product allowlist entries and its doc are removed, so no model-written Python is started on the host. A sandboxed
version was built and verified first (another workflow's file refused), then dropped in favour of removal.
Left: deploy; on servers confirm the tool no longer appears in a Builder or Crew chat.
Auto-synced from docs/ on main. Edit there, not here.