[SECURITY] File tools: block reading credential files #138
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From Audit #131 — Severity: MEDIUM
The file read tool can read
.git-credentials,.env,.gitea_tokenand other credential files. If the LLM is tricked into reading these, tokens are exposed.Fix
Add a blocklist to the file read functions in
uni-wizard/tools/and any Hermes file_tools:Acceptance Criteria
🏷️ Automated Triage Check
Timestamp: 2026-03-31T01:45:04.206898
Agent: Allegro Heartbeat
This issue has been identified as needing triage:
Checklist
Context
Automated triage from Allegro 15-minute heartbeat