Stop shell Excel builds, default write_file paths, and cap short-intent tool rounds.

Refuse openpyxl/pandas-to_excel via run_command, auto-write content-only files under tmp/, and limit WhatsApp ops short intents to 8 tool rounds by default.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-10 23:21:23 +08:00
parent a5ebabbaae
commit d8bc08ee0d
6 changed files with 162 additions and 13 deletions

View file

@ -5,6 +5,26 @@ from typing import Any
from runtime.tools.base import ToolSpec
from runtime.tools.public.local_sdk import get_local_adapter
_XLSX_SHELL_MARKERS = (
"openpyxl",
"xlsxwriter",
"to_excel(",
"workbook(",
"load_workbook(",
)
def _looks_like_xlsx_via_shell(command: str) -> bool:
"""Detect agents trying to build Excel via shell/python instead of write_xlsx."""
low = str(command or "").lower()
if not low:
return False
if any(m in low for m in _XLSX_SHELL_MARKERS):
return True
if ".xlsx" in low and any(tok in low for tok in ("python", "pip", "pandas", "-c ", "import ")):
return True
return False
def run_command_tool() -> ToolSpec:
def _handler(args: dict[str, Any]) -> dict[str, Any]:
@ -19,13 +39,29 @@ def run_command_tool() -> ToolSpec:
"hint": "Pass command (aliases: cmd, shell).",
"example": {"command": "echo hello", "timeout": 60},
}
if _looks_like_xlsx_via_shell(command):
return {
"ok": False,
"error_code": "xlsx_via_shell_forbidden",
"error": "xlsx_via_shell_forbidden",
"failure_class": "schema_validation",
"retry_forbidden": True,
"hint": (
"Do not build Excel via run_command/openpyxl/pandas. "
"Use ume_alarm_xlsx_report or write_xlsx(deliverable=true) instead."
),
"fallback_tools": ["ume_alarm_xlsx_report", "write_xlsx"],
}
cwd = str(args.get("cwd") or args.get("workdir") or "").strip() or None
timeout = int(args.get("timeout") or 300)
return get_local_adapter().run_command(command=command, cwd=cwd, timeout=timeout)
return ToolSpec(
name="run_command",
description="Run a shell command via local backend. Prefer cmd aliases: command/cmd/shell.",
description=(
"Run a shell command via local backend. Prefer cmd aliases: command/cmd/shell. "
"Do not use this to build .xlsx (use write_xlsx / ume_alarm_xlsx_report)."
),
parameters={
"type": "object",
"properties": {
@ -48,4 +84,4 @@ def run_command_tool() -> ToolSpec:
)
__all__ = ["run_command_tool"]
__all__ = ["run_command_tool", "_looks_like_xlsx_via_shell"]

View file

@ -1,5 +1,6 @@
from __future__ import annotations
from datetime import datetime, timezone
from typing import Any
from runtime.tools.base import ToolSpec
@ -14,21 +15,31 @@ def _resolve_write_path(args: dict[str, Any]) -> str:
return ""
def _default_write_path() -> str:
stamp = datetime.now(timezone.utc).strftime("%Y%m%dT%H%M%SZ")
return f"tmp/write_{stamp}.txt"
def write_file_tool() -> ToolSpec:
def _handler(args: dict[str, Any]) -> dict[str, Any]:
raw = _resolve_write_path(args)
if not raw:
return {
"ok": False,
"error": "path_required",
"hint": "Pass path (or file/filename) relative to workspace root.",
"example": {"path": "tmp/notes.txt", "content": "hello", "mode": "overwrite"},
}
content = args.get("content")
if content is None:
content = args.get("text")
if content is None:
content = args.get("body")
auto_path = False
if not raw:
if content is None:
return {
"ok": False,
"error": "path_required",
"hint": "Pass path (or file/filename) relative to workspace root.",
"example": {"path": "tmp/notes.txt", "content": "hello", "mode": "overwrite"},
}
# Production WA agents often omit path; default under tmp/ instead of schema-fail looping.
raw = _default_write_path()
auto_path = True
content_s = "" if content is None else str(content)
mode = str(args.get("mode") or "overwrite").strip().lower()
try:
@ -42,13 +53,18 @@ def write_file_tool() -> ToolSpec:
p.write_text(p.read_text(encoding="utf-8", errors="replace") + content_s, encoding="utf-8")
else:
p.write_text(content_s, encoding="utf-8")
return {"ok": True, "path": str(p), "bytes": p.stat().st_size}
out: dict[str, Any] = {"ok": True, "path": str(p), "bytes": p.stat().st_size}
if auto_path:
out["auto_path"] = True
out["hint"] = f"No path provided; wrote content to {raw}."
return out
return ToolSpec(
name="write_file",
description=(
"Write text content to a workspace file (overwrite or append). "
"Path aliases: file, filename, file_path."
"Path aliases: file, filename, file_path. "
"If path is omitted but content is provided, writes to tmp/write_<timestamp>.txt."
),
parameters={
"type": "object",