Repository navigation
Update dependencies (moderate strategy) - #15
Merged
Merged
DryRunSecurity / General Security Analyzer
succeeded
Aug 1, 2026 in 2m 29s
DryRun Security
Details
General Security Analyzer Findings: 1 detected
⚠️ Unrestricted Filesystem Access for LLM Agent scripts/exercise-08/deepagent_sast_demo.py (click for details)
| Type | Unrestricted Filesystem Access for LLM Agent |
| Description | The FilesystemBackend is configured with virtual_mode=False, which according to deepagents documentation explicitly disables all path-based security guardrails. When virtual_mode=False, the root_dir parameter is not enforced as a boundary, and paths are resolved relative to the current working directory or as absolute paths. This grants the LLM agent unrestricted read/write access to the entire host filesystem, not just the intended repo directory. Combined with the FetchURLTool (which can fetch external URLs), an attacker could use prompt injection to trick the agent into reading sensitive files (credentials, configs, keys) anywhere on the filesystem or writing malicious files. |
| Filename | scripts/exercise-08/deepagent_sast_demo.py |
| CodeLink | nextgen/scripts/exercise-08/deepagent_sast_demo.py Lines 34 to 37 in c2817a7 |
Loading