Module: Nanobot::Agent::Tools::WorkspaceSandbox

Included in:
EditFile, ListDir, ReadFile, WriteFile
Defined in:
lib/nanobot/agent/tools/filesystem.rb

Overview

Shared module for workspace directory sandboxing. Ensures paths cannot escape the allowed directory via prefix tricks (e.g., /home/user/workspace_evil bypassing /home/user/workspace) or symlink-based escapes (e.g., ln -s /etc /workspace/escape).

Constant Summary collapse

PROTECTED_FILENAMES =

Bootstrap files that shape the agent's system prompt. The agent must not modify these to prevent self-modification attacks (e.g., prompt injection rewriting SOUL.md to alter the agent's behavior persistently).

%w[
  AGENTS.md SOUL.md USER.md TOOLS.md IDENTITY.md MEMORY.md
].freeze