Found live: a chat request to restart caddy (the reverse proxy for the whole fleet) executed instantly over SSH with zero approval. Root cause was in request_execution's legacy handler — restart, pct_exec, and systemctl (outside enable/disable) executed immediately with a hardcoded risk_class='reversible_low' that was never actually checked against anything, bypassing the classifier entirely. Only the `run` tool's commands were ever gated. Extracted the run tool's classify -> execute-or-queue logic into a shared classifyAndGate() and route restart/pct_exec/systemctl through it too, so every mutating path — regardless of which tool the model reaches for — gets the same read-only/config-mutation/destructive classification and approval gate. systemctl restart is already covered by an existing classifier test (config_mutation), so no new test needed; the gap was that request_execution never called the classifier at all. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
69 KiB
69 KiB