Skip to content

Fix implementations to use the correct tool names.#5

Merged
Scrattlebeard merged 1 commit intobugfix/command-safety-and-security-audit-extension-metadatafrom
bugfix/fix-tool-names-in-security-extensions
Feb 2, 2026
Merged

Fix implementations to use the correct tool names.#5
Scrattlebeard merged 1 commit intobugfix/command-safety-and-security-audit-extension-metadatafrom
bugfix/fix-tool-names-in-security-extensions

Conversation

@Scrattlebeard
Copy link
Collaborator

Add missing patterns from PR 6569
Add README.mds

Add missing patterns from PR 6569
Add README.mds
@Scrattlebeard Scrattlebeard merged commit 664fdcc into bugfix/command-safety-and-security-audit-extension-metadata Feb 2, 2026
Reapor-Yurnero pushed a commit that referenced this pull request Feb 14, 2026
#5)

* fix(security): sanitize error responses to prevent information leakage

Replace raw error messages in HTTP responses with generic messages.
Internal error details (stack traces, module paths, error messages)
were being returned to clients in 4 gateway endpoints.

* fix: sanitize 2 additional error response leaks in openresponses-http

Address CodeRabbit feedback: non-stream and streaming error paths in
openresponses-http.ts were still returning String(err) to clients.

* fix: add server-side error logging to sanitized catch blocks

Restore err parameter and add logWarn() calls so errors are still
captured server-side for diagnostics while keeping client responses
sanitized. Addresses CodeRabbit feedback about silently discarded errors.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant