Agent Plugin Skills cannot enforce parent tool restrictions during setup
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 30/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- typescript
- Lĩnh vực
- developer-experience, security, tooling
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện luồng thiết lập của một Plugin Skill được chọn trong giao diện người dùng desktop của MiniMax Code, đồng thời quan sát MCP helper và quyền truy cập Terminal của phiên cha. Xem xét cách Skill prompt và các bộ chọn công cụ agent.md tùy chỉnh được xử lý. Công việc được xem là hoàn tất khi các tác giả plugin có một hạn chế đối với phiên cha do host áp đặt, hiển thị cho người dùng và có thể kiểm thử, hoặc một giao diện thiết lập gốc ngăn các thao tác shell hoặc tệp không được ủy quyền.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
Agent Plugin Skills currently cannot enforce a tool restriction on the parent MiniMax Code session while performing plugin-guided setup. This prevents certifying autonomous, native-only setup flows for security-sensitive plugins.
Environment
- MiniMax Code: 3.0.68.134
- Plugin type: Agent Plugin, imported from a public Git repository
- Setup initiated from a selected Plugin Skill in a disposable MiniMax profile
Reproduction
- Create or import an Agent Plugin with a Skill that guides a setup operation through MiniMax-native mechanisms (for example,
mavis agentprofile/configuration operations). - In the Skill prompt, explicitly provide all required input (including the temporary profile root) and explicitly prohibit Terminal, shell commands, HTTP requests, direct store edits, and direct agent workflow/system-prompt/project-file changes.
- Start the Skill from the MiniMax Code desktop UI.
- The Skill can invoke its MCP helper, but the parent session still has Terminal available and may invoke it (observed: a directory listing command) to inspect the plugin or profile before continuing.
Actual behavior
The parent agent's available tools are not constrained by the selected Skill's instructions. Prompt-level restrictions are advisory only: Terminal remains exposed and can be used during setup.
Custom Agent agent.md tool selectors can restrict child roles, but they do not restrict the parent session executing the Plugin Skill. Therefore they cannot provide an end-to-end guarantee for a native-only, shell-free setup flow.
Expected behavior
Please provide one of these host-enforced mechanisms:
- A declarative allowlist/denylist for tools available to the parent session while a Plugin Skill is running (for example, excluding Terminal and shell); or
- A non-prompt native setup API/surface for Agent Plugins to create/update supported agent configuration safely, without asking the parent model to perform file or shell operations.
The restriction must be enforced by the host, visible to the user, and testable by plugin authors.
Impact
Without a host-enforced boundary, a plugin cannot truthfully certify autonomous setup as native-only or shell-free. For production distribution, the only safe outcomes are a supervised manual setup contract or a fail-closed block. This affects plugins that need to install or configure multi-agent roles while preserving least privilege.
Could you confirm whether a parent-session tool policy already exists (and how Plugin Skills declare it), or whether this capability/API is planned?
- Ngôn ngữ chính
- TypeScript
- Star
- 2k
- Fork
- 250
- Merge trung bình
- 7 giờ 37 phút
- Pull request đã merge (30 ngày)
- 147
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của MiniMax-AI/minimax-code
-
bug cli documentation needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
MiniMax-AI/minimax-code#299 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug cli needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
MiniMax-AI/minimax-code#128 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug desktop
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
MiniMax-AI/minimax-code#87 · 2 bình luận · 2 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug desktop needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MiniMax-AI/minimax-code#80 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug desktop needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
MiniMax-AI/minimax-code#66 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của MiniMax-AI/minimax-code
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
clawsweeper:fix-shape-clear clawsweeper:queueable-fix clawsweeper:source-repro impact:other issue-rating: 🦞 diamond lobster no-stale P2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
openclaw/openclaw#168089 · 2 bình luận · 1 reaction ·
Maintainer thường phản hồi trong vòng 1 ngày
-
✨ enhancement needs-discussion
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
-
[Bug]: [MCP/CLI] Bare loopback IP addresses (127.0.0.1:port) and hosts with ports fail to navigate due to erroneous scheme inferenceCó thể đã có người làm @alok-108 đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
microsoft/playwright#43263 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:studio type:security
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày