AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

HumanInTheLoopMiddleware Cross-Tool Edit Bypasses Target Tool'S Interrupt_on Policy

An edit decision can change a tool call from tool A to tool B, but the resulting call is evaluated only against tool A's InterruptOnConfig. If tool B has its own interrupt_on policy, it is silently skipped, allowing execution without the required human approval.

highConfidence 90%LangChainAffected V1.3.18

Origin Analysis

HumanInTheLoopMiddleware selects the interrupt_on configuration using the original tool name and after processing an edit does not re-evaluate the target tool's configuration before the revised call is routed to ToolNode.
1. Configure HumanInTheLoopMiddleware with interrupt_on for tool_a (allowed_decisions=['approve','edit']) and tool_b (allowed_decisions=['approve','reject']).\n2. Create an agent with tools tool_a and tool_b and a deterministic model that initially calls tool_a.\n3. Invoke the agent; the initial tool_a call triggers an interrupt.\n4. Resume with a Command containing an edit decision that changes the action name to tool_b.\n5. Observe that tool_b executes immediately without a second interrupt, printing 'Second interrupt: False' and executed = [('tool_b', 'edited')].

Fixing Code Block

Edge Case Audit

This change rejects previously allowed cross-tool edits to any tool listed in `interrupt_on`, potentially breaking existing workflows that relied on such edits. To roll back, remove the added guard or adjust the interrupt_on configuration. If re-evaluation of the target tool's policy is preferred over rejection, a more complex change is required. No thread-safety or concurrency regression is introduced by this simple guard.

Ecosystem Topology