fix(pi): redact private blocks before truncating prompts - #1559
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe Pi plugin now removes private-tagged content before truncating captured prompts to 2,000 characters. A regression test covers a private block that crosses the truncation limit. ChangesPi prompt redaction
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to The boundary-crossing private value is covered by the new capture test. No issue identified here needs resolution before merge. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Removing marked private text before applying the prompt limit closes the demonstrated exposure without expanding access or adding an endpoint. The assessment is limited to the prompt-capture path shown here. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The fix directly addresses the leak and includes focused regression coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Fixes private prompt leakage by redacting <private> blocks before truncation.
Changes:
- Reorders redaction and truncation in Pi prompt capture.
- Adds a wire-level regression test for boundary-straddling private blocks.
| File | Description |
|---|---|
plugin/pi/index.ts |
Redacts prompt content before truncation. |
plugin/pi/test/native-tool-contract.test.mjs |
Verifies private content never reaches /prompts. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🔗 Linked Issue
Closes #1558
🏷️ PR Type
type:bug— Bug fix📝 Summary
<private>blocks before truncating to 2,000 characters, so a block that straddles the limit can no longer lose its closing tag and leak toPOST /prompts.696eaeb).📂 Changes
plugin/pi/index.tstruncate(stripPrivateTags(text), 2000)instead ofstripPrivateTags(truncate(text, 2000))plugin/pi/test/native-tool-contract.test.mjsbefore_agent_starthook: 1,980 chars +<private>PIN=42</private>🧪 Test Plan
node --test --test-name-pattern="straddles" test/native-tool-contract.test.mjs(inplugin/pi). It failed before the fix withprivate content must never reach the wire, and passes after it.npm testinplugin/pi: 213/213 pass.git diff --checkclean.✅ Contributor Checklist
Closes #1558)type:*label to this PRCo-Authored-Bytrailers in commitsSummary by CodeRabbit