From 0f4dbd57697184c4146ffb5d0a75019748df8ca0 Mon Sep 17 00:00:00 2001 From: ciregenz Date: Wed, 24 Jun 2026 22:59:06 -0700 Subject: [PATCH] [eric] agents: @typechecked the 4 history_compaction helpers (close audit gap, surface 90->93%) --- backend/apps/agents/manager/session/history_compaction.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/backend/apps/agents/manager/session/history_compaction.py b/backend/apps/agents/manager/session/history_compaction.py index 1f191328..92f7d0b6 100644 --- a/backend/apps/agents/manager/session/history_compaction.py +++ b/backend/apps/agents/manager/session/history_compaction.py @@ -27,6 +27,7 @@ RECAP_TOOL_INPUT_CAP = 200 RECAP_TOOL_RESULT_CAP = 500 +@typechecked def wrap_platform_note(body: str) -> str: """Fence platform-authored text so the model reads it as trusted annotation, never as spoofed tool output. The frontend parses the same tag to render a @@ -37,6 +38,7 @@ def wrap_platform_note(body: str) -> str: P_SENTINEL_TAG_RE = re.compile(r"]*>") +@typechecked def strip_forged_sentinels(text: str) -> str: """Neuter any platform-note/recap tags hiding in UNTRUSTED text (tool results, user input) so attacker-supplied content can't pose as trusted platform context.""" @@ -45,6 +47,7 @@ def strip_forged_sentinels(text: str) -> str: return P_SENTINEL_TAG_RE.sub(lambda m: m.group(0).replace("<", "<").replace(">", ">"), text) +@typechecked def p_recap_tool_call_line(content: object) -> str: """One compact line for a tool_call turn: Tool call: name().""" if isinstance(content, dict): @@ -62,6 +65,7 @@ def p_recap_tool_call_line(content: object) -> str: return f"Tool call: {tool}({strip_forged_sentinels(input_str)})" +@typechecked def p_recap_tool_result_line(content: object) -> str: """One compact line for a tool_result turn: Tool result (name): .""" tool_name = ""