Expand description
Runtime safeguards for addon tool output (#866).
An addon’s tool result is untrusted content that flows straight into the
model context — both an exfiltration surface (the addon could echo back a
secret it read) and a prompt-injection surface. Before the gateway hands a
downstream result to the model (crate::core::mcp_catalog::proxy), it runs the
output through the same redaction the shell layer uses (single source of
truth: crate::core::redaction + crate::core::secret_detection) and
records an audit line tagging the bytes as untrusted, attributed to the
originating server.
Functions§
- scrub_
output - Redact secrets from a downstream addon’s tool output and emit an audit trace marking it untrusted. Returns the scrubbed text the model will see.