Skip to content

fix: sanitize terminal control characters in agent output - #16

Merged
waltonseymour merged 1 commit into
OpenVanta:mainfrom
arvid-berndtsson:fix/cli-security-hardening
Oct 6, 2026
Merged

waltonseymour merged 1 commit into
OpenVanta:mainfrom
arvid-berndtsson:fix/cli-security-hardening

Conversation

@arvid-berndtsson

@arvid-berndtsson arvid-berndtsson commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Strip terminal control bytes from agent-mode TOON output after encoding.
  • Preserve TOON structural newlines and escaped string controls.

Verification

  • npm test: 16 passed using the existing @toon-format/toon 0.8.0 dependency.
  • npm run typecheck passed.
  • git diff --check passed.

OAuth/API-base safeguards are kept in the separate local worktree for follow-up.

@arvid-berndtsson

Copy link
Copy Markdown
Contributor Author

Hi, if there are any questions regarding my suggestions please feel free to ask. 😊

It would be nice to get these two things fixed.

@waltonseymour

Copy link
Copy Markdown
Contributor

Thank you for the contribution @arvid-berndtsson !

The terminal control character changes look good to merge.

I think we might want to add additional safeguards for modified API_BASE values. This prevents against sending a cached token to a modified base, but still will result in a token request with stored credentials being sent to said base.

@arvid-berndtsson arvid-berndtsson changed the title fix: bind cached tokens to their API base and sanitize agent output fix: guard OAuth credentials against API base changes Oct 3, 2026
@arvid-berndtsson arvid-berndtsson changed the title fix: guard OAuth credentials against API base changes fix: sanitize terminal control characters in agent output Oct 3, 2026
@arvid-berndtsson
arvid-berndtsson force-pushed the fix/cli-security-hardening branch from b842b24 to 8411503 Compare October 3, 2026 11:27
@arvid-berndtsson

Copy link
Copy Markdown
Contributor Author

Hi @waltonseymour! I’ve split the original PR into separate changes to make them easier to review. PR #16 now contains only the terminal-output sanitization changes you said looked good. I’ve kept the API_BASE/OAuth safeguards separate as follow-up work.

Please let me know if you’d like any other changes to this PR.

One note: this change sanitizes agent-mode response output; it doesn’t cover every CLI stdout/stderr path, such as downloaded media, dry-run details, or verbose/error messages. I’ve kept those paths out of this PR’s scope.

@waltonseymour
waltonseymour merged commit da0e82f into OpenVanta:main Oct 6, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants