fix(agent): unwrap nested tool call arguments - #10076
Draft
NayukiChiba wants to merge 1 commit into
Draft
Conversation
Contributor
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. If the unwrapping condition is wrong, a previously rejected or malformed tool call could invoke a handler with unintended arguments, including executing an unintended local shell command. Reverting prevents future calls from taking that path, but any side effects from commands or other tools that already ran would remain.
NayukiChiba
marked this pull request as draft
September 14, 2026 02:45
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #10074
当工具调用参数被额外包装为
{"arguments": {"command": "..."}},甚至出现多层嵌套时,核心会直接将外层arguments作为关键字参数传给工具,导致参数不匹配,工具无法执行。Modifications / 改动点
arguments包装层。arguments一个键且值为对象的包装结构。arguments参数及现有权限检查。Screenshots or Test Results / 运行截图或测试结果
Checklist / 检查清单
😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
/ 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。
👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
/ 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”。
🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in
requirements.txtandpyproject.toml./ 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到
requirements.txt和pyproject.toml文件相应位置。😮 My changes do not introduce malicious code.
/ 我的更改没有引入恶意代码。
Summary by Sourcery
Ensure tool calls with redundant nested argument wrappers are normalized without changing valid argument handling.
Bug Fixes:
argumentswrappers before parameter filtering and hook execution, allowing affected tools to execute correctly.Enhancements:
argumentsparameters and non-wrapper argument structures while retaining existing permission checks.Tests: