Skip to content

Update dependencies (moderate strategy) - #15

Merged
cktricky merged 5 commits into
mainfrom
chore/update-dependencies-moderate
Aug 1, 2026
Merged

cktricky merged 5 commits into
mainfrom
chore/update-dependencies-moderate

Address PR review: use consistent import path and remove unused import

c2817a7
Select commit
Loading
Failed to load commit list.
DryRunSecurity / General Security Analyzer succeeded Aug 1, 2026 in 2m 29s

DryRun Security

Details

General Security Analyzer Findings: 1 detected

⚠️ Unrestricted Filesystem Access for LLM Agent scripts/exercise-08/deepagent_sast_demo.py (click for details)
Type Unrestricted Filesystem Access for LLM Agent
Description The FilesystemBackend is configured with virtual_mode=False, which according to deepagents documentation explicitly disables all path-based security guardrails. When virtual_mode=False, the root_dir parameter is not enforced as a boundary, and paths are resolved relative to the current working directory or as absolute paths. This grants the LLM agent unrestricted read/write access to the entire host filesystem, not just the intended repo directory. Combined with the FetchURLTool (which can fetch external URLs), an attacker could use prompt injection to trick the agent into reading sensitive files (credentials, configs, keys) anywhere on the filesystem or writing malicious files.
Filename scripts/exercise-08/deepagent_sast_demo.py
CodeLink
filesystem_backend = FilesystemBackend(root_dir=repo_path, virtual_mode=False)
# Skills setup — loaded into each agent's context as domain expertise
skills_dir = os.path.join(SCRIPT_DIR, "skills")