Skip to content

fix(pi): redact private blocks before truncating prompts - #1559

Merged
Alan-TheGentleman merged 1 commit into
mainfrom
fix/pi-redact-before-truncate
Sep 29, 2026
Merged

Alan-TheGentleman merged 1 commit into
mainfrom
fix/pi-redact-before-truncate

Conversation

@Alan-TheGentleman

@Alan-TheGentleman Alan-TheGentleman commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

🔗 Linked Issue

Closes #1558


🏷️ PR Type

  • type:bug — Bug fix

📝 Summary

📂 Changes

File Change
plugin/pi/index.ts truncate(stripPrivateTags(text), 2000) instead of stripPrivateTags(truncate(text, 2000))
plugin/pi/test/native-tool-contract.test.mjs Regression through the real before_agent_start hook: 1,980 chars + <private>PIN=42</private>

🧪 Test Plan

  • Focused regression (behavior change): node --test --test-name-pattern="straddles" test/native-tool-contract.test.mjs (in plugin/pi). It failed before the fix with private content must never reach the wire, and passes after it.
  • Affected package tests (behavior change): npm test in plugin/pi: 213/213 pass.
  • Other applicable local checks: git diff --check clean.

✅ Contributor Checklist

  • I linked an approved issue above (Closes #1558)
  • I added exactly one type:* label to this PR
  • I recorded actual focused regression and affected package test commands/outcomes
  • Docs updated (if behavior changed): N/A, no documented contract changes
  • Commits follow conventional commits format
  • No Co-Authored-By trailers in commits
  • I checked every changed path against the Transient Artifact Policy

Summary by CodeRabbit

  • Bug Fixes
    • Private content in prompts is now removed before truncation, preventing sensitive text from appearing in captured prompts when a private block crosses the truncation limit.
  • Tests
    • Added regression coverage to verify private content is excluded and marked as redacted in captured prompts.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 18:31
@Alan-TheGentleman Alan-TheGentleman added the type:bug Bug fix label Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 54ebc22e-b77c-4308-9ccd-c8516b400ebb

📥 Commits

Reviewing files that changed from the base of the PR and between 5a95191 and 16c4e2b.

📒 Files selected for processing (2)
  • plugin/pi/index.ts
  • plugin/pi/test/native-tool-contract.test.mjs

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The Pi plugin now removes private-tagged content before truncating captured prompts to 2,000 characters. A regression test covers a private block that crosses the truncation limit.

Changes

Pi prompt redaction

Layer / File(s) Summary
Redact captured prompts before truncation
plugin/pi/index.ts, plugin/pi/test/native-tool-contract.test.mjs
The prompt capture path removes private-tagged content before truncation. The regression test checks that the captured request excludes PIN=42 and includes [REDACTED].

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: gentleman-programming, dnlrsls

Merge Risk: ⚪ Minimal · up to 16c4e

The boundary-crossing private value is covered by the new capture test. No issue identified here needs resolution before merge.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 16c4e

Removing marked private text before applying the prompt limit closes the demonstrated exposure without expanding access or adding an endpoint. The assessment is limited to the prompt-capture path shown here.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The affected exposure is captured Pi prompt content sent to the existing /prompts endpoint. The changed test stub does not extend production reachability.

Security Findings and Attack Paths

  • observed — The regression supplies a private block crossing the old truncation limit and verifies that its value is absent from the serialized /prompts request while a redaction marker remains.

Trust Boundaries and Controls

  • observed — The Pi hook now applies the private-block control before the length limit and before handing the body to the outbound request path. The unchanged helper only protects content enclosed by matching private tags.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: redacting private blocks before truncating prompts in Pi.
Linked Issues check ✅ Passed Issue #1558 requires redaction before the 2,000-character truncation so a private block cannot lose its closing tag and leak. plugin/pi/index.ts now applies stripPrivateTags(finalContent) before `…
Out of Scope Changes check ✅ Passed The pull request changes only Pi prompt-capture ordering and adds its focused regression test. Both changes directly support Issue #1558. No unrelated change is demonstrated.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The fix directly addresses the leak and includes focused regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Fixes private prompt leakage by redacting <private> blocks before truncation.

Changes:

  • Reorders redaction and truncation in Pi prompt capture.
  • Adds a wire-level regression test for boundary-straddling private blocks.
File Description
plugin/​pi/​index.ts Redacts prompt content before truncation.
plugin/​pi/​test/​native-tool-contract.test.mjs Verifies private content never reaches /prompts.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Alan-TheGentleman
Alan-TheGentleman added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 85eca98 Sep 29, 2026
25 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(pi): private blocks straddling the prompt truncation limit leak

2 participants