Module: Nanobot::Agent::Tools::WorkspaceSandbox
- Defined in:
- lib/nanobot/agent/tools/filesystem.rb
Overview
Shared module for workspace directory sandboxing. Ensures paths cannot escape the allowed directory via prefix tricks (e.g., /home/user/workspace_evil bypassing /home/user/workspace) or symlink-based escapes (e.g., ln -s /etc /workspace/escape).
Constant Summary collapse
- PROTECTED_FILENAMES =
Bootstrap files that shape the agent's system prompt. The agent must not modify these to prevent self-modification attacks (e.g., prompt injection rewriting SOUL.md to alter the agent's behavior persistently).
%w[ AGENTS.md SOUL.md USER.md TOOLS.md IDENTITY.md MEMORY.md ].freeze