Advanced
Open
Pro
A Gate That Checked the Wrong Thing
A harness enforces "the agent may only write inside /workspace."
The check is implemented as: take the path argument, verify the
string starts with /workspace/, then hand the original path to
the file-writing executor.
During a session, the agent (following instructions embedded in a
README it had fetched) created /workspace/notes as a symlink to
/home/dev/.ssh, then wrote to /workspace/notes/authorized_keys.
The check passed. The write landed outside the workspace.
- Name the failure class and explain precisely where the harness's reasoning broke.
- Fix the check. Then identify at least two other places in a typical harness where the same class of bug appears in a different costume.
- The team's proposed fix is "deny paths containing
..and block symlink creation." Evaluate it.
Share this question