Skip to content

✨ feat(agent): block nested sub-agent calls#15575

Merged
arvinxx merged 3 commits into
canaryfrom
feat/block-nested-sub-agent
Jun 9, 2026
Merged

✨ feat(agent): block nested sub-agent calls#15575
arvinxx merged 3 commits into
canaryfrom
feat/block-nested-sub-agent

Conversation

@arvinxx

@arvinxx arvinxx commented Jun 9, 2026

Copy link
Copy Markdown
Member

Summary

Sub-agents must not recursively spawn further sub-agents. This plumbs an isSubAgent flag from the spawning thread through the conversation / operation / tool-call metadata, and refuses nested dispatch at every layer so a sub-agent can neither call nor be configured with the sub-agent tool.

  • Spawn sidestreamingExecutor marks the spawned sub-agent context with isSubAgent: true.
  • Config sideaiAgent strips the LobeAgent tool from a sub-agent's plugin config (isSubAgent → remove LobeAgentIdentifier).
  • Tool gate — the client builtin-tool executor (@lobechat/builtin-tool-lobe-agent) and the server tool runtime (lobeAgent.ts) both return a clear Sub-agent calls cannot be triggered from within another sub-agent. error when ctx.isSubAgent.
  • Dispatch gateRuntimeExecutors blocks both single and batch sub-agent dispatch when state.metadata.isSubAgent === true.
  • Flag carried through ConversationContext, AgentExecutionContext, builtin-tool ctx, agentRuntime + toolExecution types.

Change Type

  • ✨ New feature (guardrail)

How to Test

  • bunx vitest run on the four touched suites — 166 tests pass:
    • src/server/modules/AgentRuntime/__tests__/RuntimeExecutors.test.ts
    • src/server/services/toolExecution/serverRuntimes/__tests__/lobeAgent.test.ts
    • src/store/chat/slices/plugin/action.test.ts
    • src/store/tool/slices/builtin/executors/index.test.ts
  • Manual: from a sub-agent thread, attempt a sub-agent tool call → returns the nested-not-allowed error instead of spawning.

🤖 Generated with Claude Code

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @arvinxx, you have reached your weekly rate limit of 500000 diff characters.

Please try again later or upgrade to continue using Sourcery

@vercel

vercel Bot commented Jun 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
lobehub Ready Ready Preview, Comment Jun 9, 2026 6:48pm

Request Review

@dosubot dosubot Bot added size:L This PR changes 100-499 lines, ignoring generated files. feature:agent Assistant/Agent configuration and behavior labels Jun 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

isSubAgent, // Pass isSubAgent to filter out lobe-agent tool in sub-agent context

P2 Badge Keep visual fallback from re-enabling sub-agent tools

For client-side sub-agent runs, passing isSubAgent only filters the resolved plugin list before internal_createAgentState adds runtime plugins; if the sub-agent has visual media and uses a non-vision/non-video model, the later visual-understanding injection re-adds LobeAgentManifest.identifier, which exposes callSubAgent/callSubAgents in the sub-agent's tool schema. This violates the new config-side guard and can make the model attempt blocked nested dispatches instead of never seeing those tools.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +599 to +600
if (appContext?.isSubAgent) {
agentConfig.plugins = agentConfig.plugins?.filter((id) => id !== LobeAgentIdentifier);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Filter lobe-agent after visual fallback injection

When a server-side sub-agent runs with image/video context on a model that lacks the corresponding capability and visual understanding is configured, this early filter is undone later by the turn-scoped tool injection that appends LobeAgentManifest.identifier for visual analysis. That exposes the whole lobe-agent manifest, including callSubAgent/callSubAgents, to the sub-agent even though the new guard is meant to prevent sub-agents from being configured with sub-agent tools; filter the sub-agent APIs after the visual fallback is added or split visual analysis from the sub-agent tool.

Useful? React with 👍 / 👎.

@codecov

codecov Bot commented Jun 9, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 57.50000% with 34 lines in your changes missing coverage. Please review.
✅ Project coverage is 67.62%. Comparing base (5b4b50e) to head (8db338b).
⚠️ Report is 2 commits behind head on canary.

Additional details and impacted files
@@            Coverage Diff             @@
##           canary   #15575      +/-   ##
==========================================
- Coverage   67.62%   67.62%   -0.01%     
==========================================
  Files        3354     3354              
  Lines      338663   338740      +77     
  Branches    36446    35266    -1180     
==========================================
+ Hits       229027   229078      +51     
- Misses     109445   109471      +26     
  Partials      191      191              
Flag Coverage Δ
app 60.16% <57.50%> (+<0.01%) ⬆️
database 97.64% <ø> (ø)
packages/agent-manager-runtime 49.69% <ø> (ø)
packages/agent-runtime 81.06% <ø> (ø)
packages/app-config 44.58% <ø> (ø)
packages/builtin-tool-lobe-agent 20.07% <ø> (ø)
packages/context-engine 84.12% <ø> (ø)
packages/conversation-flow 91.29% <ø> (ø)
packages/device-gateway-client 90.18% <ø> (ø)
packages/env 11.42% <ø> (ø)
packages/eval-dataset-parser 95.15% <ø> (ø)
packages/eval-rubric 76.11% <ø> (ø)
packages/fetch-sse 87.28% <ø> (ø)
packages/file-loaders 87.89% <ø> (ø)
packages/locales 0.87% <ø> (ø)
packages/memory-user-memory 74.99% <ø> (ø)
packages/model-bank 99.99% <ø> (ø)
packages/model-runtime 84.23% <ø> (ø)
packages/prompts 72.51% <ø> (ø)
packages/python-interpreter 92.90% <ø> (ø)
packages/ssrf-safe-fetch 0.00% <ø> (ø)
packages/trpc 40.43% <ø> (ø)
packages/types 35.15% <ø> (ø)
packages/utils 85.03% <ø> (ø)
packages/web-crawler 88.08% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

Components Coverage Δ
Store 68.40% <56.25%> (+0.02%) ⬆️
Services 54.25% <ø> (ø)
Server 97.03% <ø> (ø)
Libs 54.03% <ø> (-0.17%) ⬇️
Utils 82.08% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

arvinxx and others added 3 commits June 10, 2026 02:37
Sub-agents must not recursively spawn further sub-agents. Plumb an
`isSubAgent` flag from the spawning thread through the conversation /
operation / tool-call metadata, and refuse nested dispatch at every layer:

- streamingExecutor marks the spawned sub-agent context with `isSubAgent`
- aiAgent strips the LobeAgent tool from a sub-agent's plugin config
- client builtin-tool executor + server tool runtime return a clear error
- RuntimeExecutors blocks both single and batch sub-agent dispatch

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…ntext

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Group sub-agents are real agent dispatches and must keep the ability to
spawn their own sub-agents; only the LobeAgent-tool virtual sub-agent
path should carry isSubAgent. Drop the flag from execSubAgentTask.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@arvinxx arvinxx force-pushed the feat/block-nested-sub-agent branch from 6fda353 to 8db338b Compare June 9, 2026 18:38
@arvinxx arvinxx merged commit 1260756 into canary Jun 9, 2026
35 checks passed
@arvinxx arvinxx deleted the feat/block-nested-sub-agent branch June 9, 2026 20:00
arvinxx added a commit that referenced this pull request Jun 10, 2026
# 🚀 LobeHub Release (20260610)

**Release Date:** June 10, 2026  
**Since v2.2.2:** 131 merged PRs · 13 contributors

> This weekly release strengthens agent collaboration across cloud,
desktop, CLI, and workspace flows, with steadier runtime behavior and a
broader foundation for workspace-scoped data.

---

## ✨ Highlights

- **Agent execution across devices** — Unifies per-device working
directories, project skill discovery, and sub-agent suspend/resume
behavior across server, QStash, and device RPC flows. (#15543, #15566,
#15481, #15620, #15591)
- **Connector and sandbox platform** — Expands connector permissions,
custom OAuth MCP connector onboarding, sandbox provider support, and
user-uploaded file sync into cloud sandbox runs. (#15463, #15546,
#15184, #15550)
- **Desktop and CLI reliability** — Fixes desktop cold-start,
auto-update, Windows build, CLI skill discovery, and `lh connect` agent
dispatch paths. (#15547, #15525, #15527, #15562, #15632, #15634)
- **Pages and sharing** — Refreshes topic sharing, improves Page Editor
layout behavior, and routes Page Agent tool execution through the
server-side editor path. (#15581, #15556, #15588, #15023, #15610)
- **Model availability and provider updates** — Adds user-scoped LobeHub
model availability, Claude Fable 5, Qwen thinking preservation, and
MiniMax M3 updates. (#15590, #15639, #13494, #15376)

---

## 🏗️ Core Product & Architecture

### Agent Runtime & Heterogeneous Agents

- Improves sub-agent lifecycle handling, including async suspend/resume,
queue-mode QStash resume delivery, and blocking nested sub-agent calls.
(#15481, #15620, #15575)
- Stabilizes heterogeneous agent ingestion and streaming with raw stream
dumps, per-turn usage, image forwarding on regenerate, and
duplicate-text fixes. (#15602, #15577, #15592, #15585)
- Adds execution-device and working-directory controls across device
RPC, legacy defaults, and remote-spawned Claude Code sessions. (#15543,
#15566, #15591, #15572)
- Improves runtime diagnostics and compatibility, including Gemini
multimodal output capture, abort stream semantics, and trace quality
analysis. (#15535, #13677, #15508)

---

## 📱 Platforms, Integrations & UX

### Connectors, Sandbox & Tools

- Ships API-level connector tool permissions, custom OAuth MCP connector
onboarding, and connector-first runtime execution. (#15463, #15546)
- Adds sandbox provider support, cloud sandbox file sync, and safer
external URL file input handling with SSRF validation. (#15184, #15550,
#12657)
- Improves tool visibility and execution with pinned app-fixed tools,
ANSI output rendering, gateway-tunneled MCP calls, and automatic
headless tool runs. (#15509, #15516, #15469, #15492)

### Desktop, CLI & Web UX

- Restores desktop startup and reload behavior, preserves IPC error
causes, and keeps the tab bar new-tab action visible across routes.
(#15547, #15597, #15638)
- Fixes desktop update and build stability for browser quit guards,
macOS update signing, and Windows Visual Studio detection. (#15525,
#15527, #15562)
- Shows the plan-limit upgrade UI on desktop builds. (#15628)
- Adds the Agent Run delivery checker and fixes CLI device dispatch plus
skill list/search output. (#15489, #15634, #15632)
- Refreshes onboarding, auth source preservation, topic UI states,
referral/Fable campaign copy, and chat-input control bar behavior.
(#15629, #15544, #15573, #15614, #15616, #15617, #15622, #15643)

---

## 🔒 Security, Reliability & Rollout Notes

- External URL file input now includes SSRF validation for safer Google
file handling. (#12657)
- Database workspace-scope migrations are part of this release;
self-hosted operators should run the normal migration path before
serving the updated app. (#15446, #15465, #15468, #15472)
- The release branch was re-cut from `canary` and includes the latest
`main` release-version commit so `v2.2.2` is the verified compare base.

---

## 👥 Contributors

@ONLY-yours, @sxjeru, @hardy-one, @xujingli, @hezhijie0327, @Coooolfan,
@arvinxx, @tjx666, @Innei, @rivertwilight, @rdmclin2, @cy948,
@AmAzing129

**Full Changelog**:
v2.2.2...release/weekly-20260610-recut-3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

feature:agent Assistant/Agent configuration and behavior size:L This PR changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant