fix: enable only curated agent skills

This commit is contained in:
2026-07-11 12:25:52 +08:00
parent 96e120e02c
commit 17c0536958
6 changed files with 14 additions and 9 deletions
+4 -1
View File
@@ -151,7 +151,9 @@ export async function runAgent(req: RunRequest): Promise<RunResult> {
type QueryOptions = NonNullable<Parameters<typeof query>[0]["options"]>;
const options: QueryOptions = {
cwd: security.cwd,
tools: [...toolConfig.tools],
// `skills` controls discovery/allowlisting, but an explicit `tools`
// list still has to expose the Skill dispatcher itself.
tools: [...toolConfig.tools, "Skill"],
allowedTools: [...toolConfig.allowedTools],
maxTurns: cap,
includePartialMessages: true,
@@ -169,6 +171,7 @@ export async function runAgent(req: RunRequest): Promise<RunResult> {
// The project workspace is untrusted input. Do not load user/project
// settings that could widen tools, hooks, MCP servers, or sandbox paths.
settingSources: [],
settings: { disableBundledSkills: true },
plugins: [{ type: "local", path: security.skillPluginRoot, skipMcpDiscovery: true }],
skills: [...security.skillIds],
strictMcpConfig: true,