Skip to content

Scan operator-supplied text carried by tool approval decisions (Human-in-the-loop) - #16

Merged
veeqtoh merged 4 commits into
mainfrom
feat/scan-approval-decisions
Jul 31, 2026
Merged

Scan operator-supplied text carried by tool approval decisions (Human-in-the-loop)#16
veeqtoh merged 4 commits into
mainfrom
feat/scan-approval-decisions

Conversation

@veeqtoh

@veeqtoh veeqtoh commented Jul 31, 2026

Copy link
Copy Markdown
Member

Motivation and Context

Closes #14

Dependencies

N/A

Test Instructions

Run composer test

veeqtoh added 4 commits July 31, 2026 00:41
Adds a "Tool approval resumes" section to both middleware pages covering
what is scanned, how each action behaves, how to read the logs, and how to
opt out. Documents the new scan_approval_decisions option in the config
reference.

Extends the security notes with an explicit statement of what Intercept can
and cannot inspect. Tool results, attachments, conversation history, and the
model's response never pass through the pipeline, which matters for indirect
prompt injection and should not be left to be discovered.

Also corrects the supported entity list, which had been missing mac_address
and url since 0.1.7.
@veeqtoh
veeqtoh force-pushed the feat/scan-approval-decisions branch from 855ee55 to 1214e43 Compare July 31, 2026 00:56
@veeqtoh
veeqtoh merged commit 55514da into main Jul 31, 2026
2 checks passed
@veeqtoh
veeqtoh deleted the feat/scan-approval-decisions branch July 31, 2026 00:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scan operator-supplied text carried by tool approval decisions (Human-in-the-loop)

1 participant