deepseek-harness/docs/core-data-structures
Tianyi Cui bb9ae2ba99 docs(bash): reframe stdin/env — the scrub is the security control, not a trust boundary
Address review: the "trusted-plugin surface" framing overstated the security
story. A model driving the `bash` tool already has equivalent power to set env
vars and feed stdin through ordinary shell syntax (`FOO=bar cmd`, heredocs), so
the `env`/`stdin` seam fields grant it no new capability — and they cannot
exfiltrate the harness's ambient credentials, because the credential SCRUB in
dsh-bash-local (which strips *KEY*/*SECRET*/*TOKEN* from process.env before the
child sees it) is the actual control, and it works regardless of these fields
(tool-call args are static JSON, never shell-evaluated).

So drop the "dangerous / trusted-plugin boundary" language across the RFC, the
three bash-package READMEs, the bash/src/types.ts JSDoc, and docs/bash.md (both
the type-equiv blocks — kept 1:1 with source — and the prose). The reality that
remains: the `bash` tool doesn't EXPOSE env/stdin as parameters because they'd
be redundant with shell syntax; the fields exist for in-process plugins (the
hooks bridges) to pass a JSON payload + CLAUDE_* vars cleanly. The guard test is
kept but reframed: it catches a future `...args` spread that would silently
forward model input into the post-scrub env merge, NOT a trust wall. No code or
behavior change.
2026-07-02 04:08:24 +08:00
..
bash.md docs(bash): reframe stdin/env — the scrub is the security control, not a trust boundary 2026-07-02 04:08:24 +08:00
compaction.md fix(compact): harden summarization convergence 2026-06-29 16:56:44 +08:00
core.md docs(events): fix stale turn-mirror references caught in review 2026-07-02 03:47:37 +08:00
llm-streaming.md simplify(llm): drop unconsumed adapter-change event and assembled call surfaces 2026-06-21 01:27:41 +08:00
persistence.md docs: address review sync gaps 2026-07-01 12:56:13 +08:00
session.md Merge remote-tracking branch 'origin/master' into compact-basic-refactor 2026-06-30 09:13:15 +08:00
subagent.md Add the ACP subagent backend: out-of-process delegation (PR3) 2026-06-22 10:47:02 +08:00
tools.md Fix doc cross-links for the hierarchy; add package-path + shape gates 2026-06-20 23:12:14 +08:00