Skip to content

[Fix] Recognize more credential shapes before Auto assesses a call - #3388

Merged
daniel-lxs merged 2 commits into
developfrom
fix/auto-more-credential-shapes
Oct 3, 2026
Merged

daniel-lxs merged 2 commits into
developfrom
fix/auto-more-credential-shapes

Conversation

@daniel-lxs

Copy link
Copy Markdown
Member

Why

Auto asks a person whenever a credential appears in a tool call, using a list of known key shapes. A Stripe live key was not on the list, so a post carrying one was left to the model and could run.

What

The list now also covers Stripe, GitLab, Google, npm, SendGrid, Linear and Hugging Face keys, and the remaining GitHub and Slack token kinds. The same list masks these values on approval cards and in what the model is shown.

How to test

  1. Turn Auto on for a session.
  2. Have the agent call a tool with a Stripe-shaped test key in an argument.
  3. An approval card appears, with the key masked.

Unit tests cover each shape and words that only share a prefix.

The check that asks a person whenever a credential appears in a tool
call knew OpenAI, GitHub, Slack and AWS shapes. A Stripe live key
(sk_live_...) did not match, so a post carrying one was left to the
model and could run. The check now also knows Stripe, GitLab, Google,
npm, SendGrid, Linear and Hugging Face keys, and the remaining GitHub
and Slack token kinds.
@roomote-community

roomote-community Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

No code issues found. See task

  • Stripe organization API keys (sk_org_...) are not detected or redacted. (packages/types/src/integration-tool-args.ts:16)

Reviewed d9fb137

Comment thread packages/types/src/integration-tool-args.ts Outdated
Stripe organization API keys start with sk_org_, which the new Stripe
shape did not cover.
@daniel-lxs
daniel-lxs merged commit 71445e8 into develop Oct 3, 2026
22 checks passed
@daniel-lxs
daniel-lxs deleted the fix/auto-more-credential-shapes branch October 3, 2026 05:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant