Skip to content
Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
47 commits
Select commit Hold shift + click to select a range
019ea07
init attempt on guardrail interface
Reapor-Yurnero Feb 1, 2026
1ae9c11
fix some typing errors
Reapor-Yurnero Feb 1, 2026
4a6da7a
fix bug that would hang on pre request violation indefinitely
Reapor-Yurnero Feb 1, 2026
84055e5
fix web browser not seeing blocked message bug
Reapor-Yurnero Feb 1, 2026
6b0d748
fix an error from the previous fix
Reapor-Yurnero Feb 1, 2026
6d7f989
add some doc
Reapor-Yurnero Feb 1, 2026
85ab3a2
refactor: migrate guardrails to plugin hook system
Scrattlebeard Feb 1, 2026
5c74c85
Add LlamaGuard and gpt-oss-safeguard plugins. Remove guardrails confi…
Scrattlebeard Feb 1, 2026
7ff2716
refactor: add createGuardrailPlugin factory for unified guardrail API
Scrattlebeard Feb 1, 2026
965dbc0
feat: add command-safety-guard and security-audit plugins
Scrattlebeard Feb 1, 2026
fd6b621
Plugins: fix guardrail hook sequencing and short circuiting
Reapor-Yurnero Feb 2, 2026
e2fd8a1
change plugin naming to follow conventions
Reapor-Yurnero Feb 2, 2026
efc7065
remove redundant config enabled key
Reapor-Yurnero Feb 2, 2026
f646657
revert some unnecesary validation after moving to plugins
Reapor-Yurnero Feb 2, 2026
d1e1e31
remove redundant config.enable schema
Reapor-Yurnero Feb 2, 2026
6b5719b
Guardrails: GPT-OSS safeguard defaults and append mode
Reapor-Yurnero Feb 2, 2026
ce2a526
remove llama guard for the moment
Reapor-Yurnero Feb 2, 2026
211dde8
Guardrails: skip hooks for internal runs
Reapor-Yurnero Feb 2, 2026
c2bdd7d
polish the doc
Reapor-Yurnero Feb 2, 2026
1bb5876
Guardrails: add priority and attribution
Reapor-Yurnero Feb 2, 2026
a646c9a
Enhance command-safety-guard and security-audit plugins with UI hints…
Scrattlebeard Feb 2, 2026
70edfa0
Merge branch 'feat/guardrail_interface' into bugfix/command-safety-an…
Scrattlebeard Feb 2, 2026
87c6051
Fix implementations to use the correct tool names.
Scrattlebeard Feb 2, 2026
664fdcc
Merge pull request #5 from grayswansecurity/bugfix/fix-tool-names-in-…
Scrattlebeard Feb 2, 2026
a8f0f7c
Merge upstream/main
Reapor-Yurnero Feb 2, 2026
d020951
fix pnpm lint & pnpm build errors
Reapor-Yurnero Feb 2, 2026
43f4fc2
Merge grayswansecurity/openclaw#2
Reapor-Yurnero Feb 2, 2026
6b7c542
add readme for cygnal and gpt-oss-safeguard extensions
Reapor-Yurnero Feb 2, 2026
0e9293b
update doc about restart option
Reapor-Yurnero Feb 2, 2026
3b1e194
fix a typo introduced in command-safety-guard
Reapor-Yurnero Feb 2, 2026
e37120d
Add OpenClaw-specific API link
nwinter Feb 3, 2026
020918e
Update pnpm-lock.yaml for command-safety-guard extension
nwinter Feb 3, 2026
8dc07d2
Format extension files and escape pipe in fork-bomb pattern
nwinter Feb 3, 2026
de84696
Update test to match hook contract requiring toolCallId and messages
nwinter Feb 3, 2026
ed99104
Fix tests: use lowercase tool names and updated DEFAULT_POLICY content
nwinter Feb 3, 2026
aae4098
Skip path tests on Windows (plugin only supports Unix paths)
nwinter Feb 3, 2026
df0ffd9
address greptile comments
Reapor-Yurnero Feb 3, 2026
87e03a9
address false positves in security-audit extension for redirection
Reapor-Yurnero Feb 3, 2026
0b6d963
fix formatting issue in previous commit
Reapor-Yurnero Feb 3, 2026
495f859
address dropped tool return metadata on block
Reapor-Yurnero Feb 3, 2026
d4bea63
address more comments
Reapor-Yurnero Feb 3, 2026
51fcebe
fix type error
Reapor-Yurnero Feb 3, 2026
f1aac5f
Merge upstream/main
Reapor-Yurnero Feb 9, 2026
0a3e77d
Merge upstream/main
Reapor-Yurnero Feb 12, 2026
1141b52
Merge remote-tracking branch 'upstream/main' into feat/guardrail_inte…
Reapor-Yurnero Feb 14, 2026
8c94a4a
Merge remote-tracking branch 'upstream/main' into feat/guardrail_inte…
Reapor-Yurnero Feb 14, 2026
a5c1013
test(memory): stabilize qmd-manager wait
Reapor-Yurnero Feb 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
fix some typing errors
  • Loading branch information
Reapor-Yurnero committed Feb 1, 2026
commit 1ae9c115f1a965167a0f474ef8a5714c95b7ee11
1 change: 1 addition & 0 deletions src/agents/cache-trace.ts
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ export type CacheTraceEvent = {
messageFingerprints?: string[];
messagesDigest?: string;
systemDigest?: string;
guardrailBlocked?: string;
note?: string;
error?: string;
};
Expand Down
30 changes: 20 additions & 10 deletions src/agents/guardrails.ts
Original file line number Diff line number Diff line change
Expand Up @@ -330,6 +330,13 @@ const GRAYSWAN_DEFAULT_TIMEOUT_MS = 30_000;

const grayswanLogger = createSubsystemLogger("guardrails/grayswan");

function makeGrayswanMessage(
role: GrayswanMonitorMessage["role"],
content: string,
): GrayswanMonitorMessage {
return { role, content };
}

function resolveGrayswanConfig(context: GuardrailContext): GrayswanGuardrailConfig | undefined {
const cfg = context.config?.guardrails?.grayswan;
if (!cfg) {
Expand Down Expand Up @@ -711,9 +718,9 @@ function createGrayswanGuardrail(): Guardrail {
return;
}
const includeHistory = stageCfg?.includeHistory !== false;
const messages = includeHistory
? [...toGrayswanMessages(input.messages), { role: "user", content: prompt }]
: [{ role: "user", content: prompt }];
const messages: GrayswanMonitorMessage[] = includeHistory
? [...toGrayswanMessages(input.messages), makeGrayswanMessage("user", prompt)]
: [makeGrayswanMessage("user", prompt)];
if (messages.length === 0) {
return;
}
Expand Down Expand Up @@ -765,9 +772,9 @@ function createGrayswanGuardrail(): Guardrail {
}
const toolSummary = buildToolCallSummary(input);
const includeHistory = stageCfg?.includeHistory !== false;
const messages = includeHistory
? [...toGrayswanMessages(input.messages), { role: "assistant", content: toolSummary }]
: [{ role: "assistant", content: toolSummary }];
const messages: GrayswanMonitorMessage[] = includeHistory
? [...toGrayswanMessages(input.messages), makeGrayswanMessage("assistant", toolSummary)]
: [makeGrayswanMessage("assistant", toolSummary)];
if (messages.length === 0) {
return;
}
Expand Down Expand Up @@ -819,9 +826,9 @@ function createGrayswanGuardrail(): Guardrail {
}
const toolText = extractToolResultText(input.result).trim();
const includeHistory = stageCfg?.includeHistory !== false;
const messages = includeHistory
? [...toGrayswanMessages(input.messages), { role: "tool", content: toolText }]
: [{ role: "tool", content: toolText }];
const messages: GrayswanMonitorMessage[] = includeHistory
? [...toGrayswanMessages(input.messages), makeGrayswanMessage("tool", toolText)]
: [makeGrayswanMessage("tool", toolText)];
if (!toolText || messages.length === 0) {
return;
}
Expand Down Expand Up @@ -886,7 +893,10 @@ function createGrayswanGuardrail(): Guardrail {
}
const includeHistory = stageCfg?.includeHistory !== false;
const historyMessages = includeHistory ? toGrayswanMessages(input.messages) : [];
const messages = [...historyMessages, { role: "assistant", content: assistantText }];
const messages: GrayswanMonitorMessage[] = [
...historyMessages,
makeGrayswanMessage("assistant", assistantText),
];
let response: GrayswanMonitorResponse | null = null;
try {
response = await callGrayswanMonitor({ cfg, messages });
Expand Down
21 changes: 9 additions & 12 deletions src/agents/pi-embedded-runner/run.ts
Original file line number Diff line number Diff line change
Expand Up @@ -370,6 +370,13 @@ export async function runEmbeddedPiAgent(

const { aborted, promptError, timedOut, sessionIdUsed, lastAssistant, guardrailBlock } =
attempt;
const guardrailBlockSummary = guardrailBlock
? {
stage: guardrailBlock.stage,
guardrailId: guardrailBlock.guardrailId,
reason: guardrailBlock.reason,
}
: undefined;

if (guardrailBlock) {
const isBeforeRequest = guardrailBlock.stage === "before_request";
Expand Down Expand Up @@ -420,11 +427,7 @@ export async function runEmbeddedPiAgent(
agentMeta,
aborted,
systemPromptReport: attempt.systemPromptReport,
guardrailBlock: {
stage: guardrailBlock.stage,
guardrailId: guardrailBlock.guardrailId,
reason: guardrailBlock.reason,
},
guardrailBlock: guardrailBlockSummary,
},
didSendViaMessagingTool: attempt.didSendViaMessagingTool,
messagingToolSentTexts: attempt.messagingToolSentTexts,
Expand Down Expand Up @@ -730,13 +733,7 @@ export async function runEmbeddedPiAgent(
agentMeta,
aborted,
systemPromptReport: attempt.systemPromptReport,
guardrailBlock: guardrailBlock
? {
stage: guardrailBlock.stage,
guardrailId: guardrailBlock.guardrailId,
reason: guardrailBlock.reason,
}
: undefined,
guardrailBlock: guardrailBlockSummary,
// Handle client tool calls (OpenResponses hosted tools)
stopReason: attempt.clientToolCall ? "tool_calls" : undefined,
pendingToolCalls: attempt.clientToolCall
Expand Down