Skip to content

Add safe-outputs.url-policy with audit and reputation URL handling - #34868

Closed
pelikhan with Copilot wants to merge 3 commits into
mainfrom
copilot/research-workflows-url-permission
Closed

pelikhan with Copilot wants to merge 3 commits into
mainfrom
copilot/research-workflows-url-permission

Conversation

Copilot AI commented May 26, 2026 •

Copy link
Copy Markdown
Contributor

safe-outputs only supported strict domain allowlisting, which made open-web research outputs unreadable by redacting nearly all citations. This PR introduces policy-driven URL sanitization so workflows can opt into broader URL handling without removing safety controls entirely.

  • Policy model for URL sanitization

    • Added safe-outputs.url-policy with:
      • allowlist (current/default behavior)
      • audit (preserve URL, log out-of-allowlist domains)
      • reputation (preserve unless flagged malicious)
    • Added safe-outputs.reputation config:
      • provider (currently google-safe-browsing)
      • api-key-secret
  • Compiler + schema integration

    • Extended workflow schema to include url-policy and reputation.
    • Added config parsing and validation for new fields.
    • Enforced reputation.provider and reputation.api-key-secret when url-policy: reputation.
    • Propagated policy/reputation settings into safe-output runtime env vars.
    • Included new meta fields in safe-outputs import merge behavior.
  • Sanitizer behavior updates

    • allowlist: unchanged redaction behavior.
    • audit: keeps external URLs intact and emits audit logs for non-allowlisted domains.
    • reputation: checks non-allowlisted URLs against Google Safe Browsing and redacts only malicious matches.
    • Added bounded in-memory caching for reputation lookups and fail-open behavior on provider/API errors.
  • Docs and contract clarity

    • Updated safe-outputs reference docs to describe policy modes and reputation configuration.
safe-outputs:
  url-policy: reputation
  reputation:
    provider: google-safe-browsing
    api-key-secret: SB_API_KEY
  allowed-domains: [default-safe-outputs]

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot this is node v24, use fetch api and use headers for secrets. Move google reputation code into own file

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Add permissive mode for safe-outputs to allow certain URLs Add safe-outputs.url-policy with audit and reputation URL handling May 26, 2026
Copilot AI requested a review from pelikhan May 26, 2026 05:40
@pelikhan pelikhan closed this May 26, 2026
Copilot stopped work on behalf of pelikhan due to an error May 26, 2026 05:47
@github-actions
github-actions Bot deleted the copilot/research-workflows-url-permission branch June 3, 2026 14:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

safe-outputs: no permissive / reputation mode — research workflows produce all-redacted URLs

2 participants