openclaw/src/security
Ayaan Zaidi a884d19bad
feat(skills): merge execution-dir skills after agent workspace skills (#125786)
* feat(skills): merge execution-dir skills after agent workspace skills

* test(skills): cover new workspace-skill-loader exports in mock factories

* fix(skills): complete multi-root invariant across sync, CLI snapshot, and prompt fallback

* fix(skills): use canonical workspace session facts
2026-08-18 17:14:09 +05:30
..
audit-channel-account-metadata.test.ts refactor: burn wrapper shadowing baseline entries (#122040) 2026-08-11 08:24:03 -07:00
audit-channel-dm-policy.test.ts fix: keep doctor security conditions as single findings (#124666) 2026-08-16 10:24:40 -07:00
audit-channel-readonly-resolution.test.ts refactor: burn wrapper shadowing baseline entries (#122040) 2026-08-11 08:24:03 -07:00
audit-channel-readonly-setup-fallback.test.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-channel-source-config-discord.test.ts refactor: burn wrapper shadowing baseline entries (#122040) 2026-08-11 08:24:03 -07:00
audit-channel-source-config-slack.test.ts refactor: burn wrapper shadowing baseline entries (#122040) 2026-08-11 08:24:03 -07:00
audit-channel-test-helpers.ts
audit-channel.collect.runtime.ts refactor: burn wrapper shadowing baseline entries (#122040) 2026-08-11 08:24:03 -07:00
audit-channel.ts fix: keep doctor security conditions as single findings (#124666) 2026-08-16 10:24:40 -07:00
audit-config-basics.test.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-config-include-perms.test.ts
audit-config-symlink.test.ts
audit-deep-code-safety.ts
audit-deep-probe-findings.ts
audit-exec-safe-bins.test.ts
audit-exec-sandbox-host.test.ts
audit-exec-surface.test.ts
audit-extra.async.test.ts feat(skills): merge execution-dir skills after agent workspace skills (#125786) 2026-08-18 17:14:09 +05:30
audit-extra.async.ts refactor(skills): split workspace loading into concept modules (#121916) 2026-08-11 01:28:20 -07:00
audit-extra.summary.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-extra.sync.test.ts fix(config): keep missing env references unavailable without rejecting literals (#125455) 2026-08-17 19:05:29 -07:00
audit-extra.sync.ts fix(config): keep missing env references unavailable without rejecting literals (#125455) 2026-08-17 19:05:29 -07:00
audit-filesystem-windows.test.ts
audit-fs.ts
audit-gateway-auth-selection.test.ts
audit-gateway-config.ts fix(config): keep missing env references unavailable without rejecting literals (#125455) 2026-08-17 19:05:29 -07:00
audit-gateway-exposure.test.ts
audit-gateway-http-auth.test.ts
audit-gateway-tools-http.test.ts
audit-gateway.test.ts fix(config): keep missing env references unavailable without rejecting literals (#125455) 2026-08-17 19:05:29 -07:00
audit-hooks-routing.test.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-loopback-logging.test.ts
audit-mcporter-registry.ts
audit-model-hygiene.test.ts
audit-model-refs.ts
audit-node-command-findings.test.ts
audit-plugin-code-safety.test.ts
audit-plugin-readonly-scope.test.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-plugins-trust.test.ts refactor(gateway): remove deferred channel load flag; 503 plugin routes until runtime ready (#117852) 2026-08-02 00:36:21 -07:00
audit-plugins-trust.ts
audit-probe-failure.test.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit-rosterless.test.ts fix(security): align agent roster default audit with runtime semantics (#124398) 2026-08-15 21:50:09 -07:00
audit-sandbox-browser.test.ts
audit-sandbox-docker-config.test.ts
audit-small-model-risk.test.ts
audit-summary.test.ts
audit-synced-folder.test.ts
audit-trust-model.test.ts fix(security): warn on main-scoped group rooms (#125054) 2026-08-17 00:37:35 -07:00
audit.deep.runtime.ts
audit.nondeep.runtime.ts
audit.runtime.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit.test-support.ts refactor: eliminate final wrapper-shadowing hazards (#122157) 2026-08-11 13:34:24 -07:00
audit.ts fix(config): keep missing env references unavailable without rejecting literals (#125455) 2026-08-17 19:05:29 -07:00
audit.types.ts fix: keep doctor security conditions as single findings (#124666) 2026-08-16 10:24:40 -07:00
channel-metadata.test.ts
channel-metadata.ts refactor(core): adopt normalization-core leaf helpers across production (#120350) 2026-08-08 12:00:49 -07:00
config-regex.ts
context-visibility.test.ts
context-visibility.ts
core-dangerous-config-flags.ts
dangerous-config-flags-core.ts
dangerous-config-flags-current-snapshot.test.ts
dangerous-config-flags-current.ts
dangerous-config-flags.test.ts
dangerous-config-flags.ts
dangerous-tools.ts feat: portals — expose agent-run dev servers to the operator (#122536) 2026-08-13 00:46:11 -07:00
dm-policy-shared.ts refactor: retire due compat-ledger surfaces (context-engine host params, deactivate alias, logging internals) (#121845) 2026-08-12 12:41:27 -07:00
exec-filesystem-policy.ts
external-content-source.ts
external-content.test.ts fix(security): harden network tool output at canonical owner boundaries (#118984) 2026-08-03 15:34:33 -07:00
external-content.ts fix(security): harden network tool output at canonical owner boundaries (#118984) 2026-08-03 15:34:33 -07:00
fix.test.ts test(security): focus permission inventory fixture (#118529) 2026-08-02 23:22:44 -07:00
fix.ts
install-policy-response.ts feat(security): require acknowledgement for policy warnings (#116489) 2026-08-15 03:58:45 +10:00
install-policy.test.ts feat(security): require acknowledgement for policy warnings (#116489) 2026-08-15 03:58:45 +10:00
install-policy.ts feat(security): require acknowledgement for policy warnings (#116489) 2026-08-15 03:58:45 +10:00
install-policy.windows.test.ts fix(security): stop recommending retired install-policy bypasses (#120011) 2026-08-06 18:45:18 -07:00
installed-plugin-dirs.ts
safe-regex.test.ts
safe-regex.ts refactor: canonicalize cache mechanics (#118262) 2026-08-02 19:33:13 -07:00
scan-paths.test.ts
scan-paths.ts
secret-equal.test.ts
secret-equal.ts
secret-mask.test.ts
secret-mask.ts
test-temp-cases.ts
windows-acl.test.ts
windows-acl.ts