Tool-call inspection guards ThinkWatch's own data directory; the docs say what protects config.yaml - #287
Merged
Conversation
… say what protects config.yaml A new built-in tool rule, `thinkwatch-data` (high: cut under enforce), fires when a tool call's path or command points into ThinkWatch's data directory: `~/.thinkwatch` (any `.thinkwatch` path component), `%APPDATA%\ThinkWatch`, and `/var/lib/thinkwatch` or `/etc/thinkwatch` on a server. The directory holds every upstream key in plain text and the settings of these protections, so reading it takes every credential in one step and writing it switches the protections off. It is a code check rather than a regex so that mentioning the path does not count: in JSON arguments only path-like keys (file_path, path, cwd, workdir, ...) and command-like keys (command, cmd, code, args, ...) are read, plus a patch file header in any value; raw tool input needs a patch header or a file command before the path on the same line. The JSON is read string by string rather than parsed, since the wall checks half-received arguments and arguments over its cap are kept only in part. The configuration reference and README now state the local boundary: 0600/0700 keeps out other users, not programs running as the same user; outbound redaction protects what leaves the machine, not the file; the control key is masked so a control-plane write cannot change it, not to hide it from local programs. Refs #286 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #286.
What
thinkwatch-data(Read or change ThinkWatch's own data; high, so cut underenforce). It fires when a tool call's path or command points into ThinkWatch's data directory:~/.thinkwatch(any.thinkwatchpath component),%APPDATA%\ThinkWatch, and/var/lib/thinkwatchor/etc/thinkwatchon a server. Case-insensitive, since macOS file systems are by default.config.yaml:0600/0700keeps out other users, not programs running as the same user; outbound redaction protects what leaves the machine, not the file; the control key is masked so that a control-plane write cannot change it, not to hide it from local programs. The generated rule table lists the new rule.Why a code check
Mentioning the path is not touching it: edits to docs, comments and answers about where the config lives are full of
~/.thinkwatch, and a regex that fires on any occurrence would cut those sessions off. So the check reads arguments by role (crates/tw-guard/src/tools/own_data.rs):file_path,path,cwd,workdir,*url, …) and command-like keys (command,cmd,code,args, …), plus a patch file header (*** Update File: …) in any value.content,new_string,descriptionand the like are ignored.apply_patch): a patch file header, or a file command (cat,sed,sqlite3,>…) before the path on the same line.~/.thinkwatchmay still become~/.thinkwatch-backup).Like the other code checks it is not in the client-config scan (that scanner only reads
re).Follow-ups outside this repo
web/src/i18nandcheck-i18n.mjs, with the next core bump.Tests
cargo fmt --all --check,cargo clippy --workspace --all-targets -D warnings,cargo test --workspace(2680 passed). New:own_dataunit tests (Claude Code / Codex / Gemini-style arguments, Windows and server paths, mentions that must not fire, half-received and truncated arguments, escapes), two streaming wall tests (a path split across fragments is cut on the fragment that completes it; an Edit whose text mentions the path passes), and the rule's presence, level andbuiltinmatcher in the tool-inspection view.🤖 Generated with Claude Code