Skip to content

v4.7.0

Choose a tag to compare

@github-actions github-actions released this 29 Jul 20:13
85b8f2a

Minor. Least privilege for agents — a subprocess gets what its function requires and nothing more, and every new tool is a conscious access. Two controls born from convergence with how a payments processor operates AI agents safely.

Added

  • Env allowlist for agent subprocesses (KJC-TSK-0693): spawned agents (coder/reviewer/tester CLIs) no longer inherit the user's whole environment — only system essentials, the CLI's own auth/config families, and KJ_* lane vars. Cloud keys, registry tokens and DB URLs never reach the child, so a compromised agent or injected prompt cannot exfiltrate what it never received. Per-agent extras (GITHUB_*/GH_* only for copilot); escapes: security.env_passthrough (names or trailing-* globs) and security.env_allowlist: false. Inspired by Akua's "temporary credentials, never a shared master key" control.
  • AI-surface inventory in kj check (KJC-TSK-0694): the project's reachable MCPs (project .mcp.json, ~/.claude.json scoped to this project, codex and gemini configs) are inventoried on every check; the first run records a baseline silently, later runs flag what APPEARED — NEW since last check: x — approved by you? — and what is gone. A nudge, never a gate: every new tool an agent gains is one more access, and an inventory nobody reconciles is the feeling of control without the control.