Repository navigation
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #9.
What this changes
textOfResultread a content block's owntextand nothing else, andframeResultandresultRecordOfare both built on it. An MCP result can carry text in two other places, and an injection in either was invisible:{ "content": [{ "type": "resource", "resource": { "uri": "file:///notes.md", "text": "..." } }] } { "structuredContent": { "summary": "..." } }So a prompt injection sitting there was never quoted, never reached
onInstructionto put the session under suspicion, and was recorded as fewer bytes than the result actually carried. All three are read now.structuredContentis stringified, because the shape is the server's and a value anywhere inside it is what an agent reads.The framing itself is untouched: it still wraps
contentin the quotation blocks, and the content still survives whole rather than being stripped.How it was verified
A new
packages/proxy/test/result-guard.test.ts— the issue is right that nothing importedframeResultorresultRecordOfdirectly before. Twelve cases; the five that matter fail onmain:resource.text, instructuredContent, and in a resource sitting beside an innocent block, each reported ascontainsInstructionbytesfor a result with a resource is greater than for the first block aloneAnd seven that pin what must not change: a
resourcewith notext, aresource_link, ordinary output,structuredContentholding only a number, an empty result and a message with no result at all are all left alone and returned unchanged byframeResult.prettier,tsc,vitestandknipall clean, on Node 24.One limit worth stating
A
resource_linkcarries a URI and no text, so there is nothing to read in it — it is covered by a test as a no-op rather than by logic. If the intent is to treat the URI itself as readable text, say so and I will add it; I did not want to invent that rule here.Checklist
pnpm format && pnpm typecheck && pnpm test && pnpm deadcodeall passany, no magic values, noconsole.*outsidecli-output.tshasInstructionShapeover more of the same text, no model, network or randomness