Skip to content

Headless/ZCode-Protocol sessions need a per-session tool fence (deny/allow list) — low-risk built-ins auto-run in every mode #952

Description

@nexiouscaliver

Context

ZCode 0.16.9 (macOS arm64), driving the ZCode Protocol app-server (and --prompt) headlessly from a local automation pipeline: sessions created via session/create {workspace}, prompts via session/send {modelSelection, content}, with the embedding client answering session/requestRuntimePreferences and brokering every interaction/requestPermission.

What's missing

There is no way to fence a headless session's tool set per session:

  1. No deny/allow channel: session/create accepts no tool configuration; the settings-object permission channel (permission.disallowedTools) is not reachable per session; /model-style TUI commands don't exist headless; there is no equivalent of a --disallowedTools/--strict-mcp-config flag for the protocol.
  2. Low-risk built-ins auto-run in every mode, with no rule consultation: measured live, in build/plan/yolo alike — the model can Read arbitrary local files, run safe-classified Bash commands (e.g. cat), and call WebSearch (query strings leave the machine) without a permission request ever reaching the client. The broker only ever sees side-effect-classified calls (Write, Edit, destructive/network Bash, WebFetch, MCP tools).
  3. permissionUpdates rules don't persist for an untrusted temp workspace (added rules never apply to later calls in the same session), so the request/response channel can't bootstrap a fence either.

Why it matters

Unattended automation that feeds untrusted text (session transcripts, archived logs) into a headless model child currently has to accept that a prompt-injected instruction can make the child read local files (credentials in dotfiles) and emit web-search queries, with no protocol-level way to prevent it. Filesystem-level guards and output validation mitigate, but the clean fix is the engine's.

Request

A per-session tool fence on the protocol surface, e.g.:

  • session/create accepting {tools: {allowed: [...], disallowed: [...]}} (built-ins + MCP tool names), enforced before the risk classifier; and/or
  • making permissionUpdates rules apply within the session that returned them (session-scoped persistence), and consulted even for low-risk-classified tools when an explicit rule exists.

Happy to share the probe scripts (a minimal python driver that reproduces each auto-run class and the broker behavior) if useful.

Activity

  1. github-actions commented on Oct 7, 2026

    @github-actions

    👋 感谢你的反馈,我们已经收到。

    • 维护者看到后会尽快回复你。
    • 状态保持为 status: 待评估,你可以随时补充信息。
    • 信息不全时我们会打上 needs: 更多信息 标签并 @ 你。

    👋 Thanks — we've received your issue.

    • A maintainer will get back to you as soon as we can.
    • Status stays at status: 待评估 (Triage); feel free to add context.
    • If we need more details, we'll add needs: 更多信息 and ping you.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions