release r007 security hardening and redesigned UI
This commit is contained in:
1 parent
514310912c
commit
65922b7f57
12 files changed
+485
-346
No files matched your search
+28
-2
@@ -29,6 +29,32 @@ export interface ToolDef {
|
||||
handler: (args: Record<string, unknown>) => Promise<string>;
|
||||
}
|
||||
|
||||
export type ToolRisk = "read" | "active" | "write" | "critical";
|
||||
|
||||
const CRITICAL_TOOLS = new Set([
|
||||
"unraid_docker_create",
|
||||
"unraid_docker_modify",
|
||||
"unraid_docker_update",
|
||||
"unraid_docker_rebuild",
|
||||
"unraid_system_shell",
|
||||
]);
|
||||
const WRITE_TOOLS = new Set([
|
||||
"unraid_docker_start",
|
||||
"unraid_docker_stop",
|
||||
"unraid_docker_restart",
|
||||
]);
|
||||
const ACTIVE_TOOLS = new Set([
|
||||
"unraid_network_audit_tcp",
|
||||
"unraid_network_lan_probe",
|
||||
]);
|
||||
|
||||
export function getToolRisk(name: string): ToolRisk {
|
||||
if (CRITICAL_TOOLS.has(name)) return "critical";
|
||||
if (WRITE_TOOLS.has(name)) return "write";
|
||||
if (ACTIVE_TOOLS.has(name)) return "active";
|
||||
return "read";
|
||||
}
|
||||
|
||||
const str = (desc: string) => ({ type: "string", description: desc });
|
||||
const int = (desc: string) => ({ type: "integer", description: desc });
|
||||
const num = (desc: string) => ({ type: "number", description: desc });
|
||||
@@ -47,7 +73,7 @@ export const TOOLS: ToolDef[] = [
|
||||
{
|
||||
name: "unraid_docker_inspect",
|
||||
description:
|
||||
"Inspect a single Docker container in detail (state, image, ports, env, mounts).",
|
||||
"Inspect a single Docker container in detail (state, image, ports, redacted environment variable names, mounts). Secret values are never returned.",
|
||||
inputSchema: {
|
||||
type: "object",
|
||||
properties: { container: str("Container name or ID") },
|
||||
@@ -306,7 +332,7 @@ export const TOOLS: ToolDef[] = [
|
||||
{
|
||||
name: "unraid_system_shell",
|
||||
description:
|
||||
"Execute a shell command on the Unraid host (as root, via /bin/sh -c) and return exit code, stdout, and stderr. Use for direct terminal access: file inspection, system commands, package info, log reading, etc. Commands run with a timeout and output is size-limited.",
|
||||
"CRITICAL: Execute an unrestricted shell command on the Unraid host as root. Keep this tool disabled unless explicitly needed for a supervised maintenance session.",
|
||||
inputSchema: {
|
||||
type: "object",
|
||||
properties: {
|
||||
|
||||
Reference in new issue
Block a user