You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(plugin): AEGIS scan-pipe on all inbound Pilot messages (#6)
* fix(plugin): regenerate package-lock.json for openclaw@2026.6.1
The plugin's package.json was bumped to openclaw ^2026.6.1 but the
lockfile still pinned 2026.5.26, so npm ci has been failing on every
push since the bump:
Invalid: lock file's openclaw@2026.5.26 does not satisfy openclaw@2026.6.1
Re-runs npm install --package-lock-only to refresh the lockfile.
Confirmed with npm ci locally — exit 0.
* feat(plugin): AEGIS scan-pipe on all inbound Pilot messages
Scan message text and media captions through `aegis scan-pipe` before
dispatching to the agent. Exit 2 from aegis drops the message with a
warning — prevents prompt injection over the Pilot network from reaching
the LLM turn.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Run AEGIS scan-pipe async to unblock the event loop
Replace the per-message spawnSync("aegis","scan-pipe") in the inbound
pipeline with a non-blocking execFile wrapper. The dispatch pipeline is
fully await-based; spawning synchronously parked the Node event loop for
the whole subprocess lifetime on every inbound message, starving every
other peer's I/O.
The new createAegisScan helper feeds candidate text on stdin, awaits the
child exit, and keeps the exit-code contract (status 2 = block, rule on
stdout). Spawn errors and timeouts resolve fail-open so a scanner outage
never silently drops all inbound DMs. The scanner is injectable via
InboundDeps/LifecycleDeps so tests run without execing a real binary.
Add coverage for the scan-pipe paths: clean pass-through, flagged/blocked
drop, and the error/timeout fail-open branch, for both the text and media
caption code paths.
---------
Co-authored-by: Teodor Calin <teodor@vulturelabs.io>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: matthew-pilot <matthew@vulturelabs.io>
0 commit comments