Repository navigation
feat(prompt-agent): a user-sim agent receives readable URLs for store-owned file parts too - #61
Conversation
…-owned file parts too prompt_agent's two sends, to the target agent and to the user agent, now go through one helper, send_and_wait, which sends and polls an A2A peer. A peer that is an agent agent-env deployed (the target, or a user-sim) is sent each file part a configured store owns as an HTTPS URL it can read, through readable_parts; any other peer, such as a human-facing endpoint named by user_a2a_url, reads the store itself and is sent the parts as they are, so no signed URL is stored there. Before, the user-sim was sent the target agent's reply parts unchanged. The target's turn is still recorded only once its parts are ready to send (send_and_wait's before_send). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sent the store's own URLs deploy_human_agent registers a human peer as a deployed agent without a sandbox. Only a user-sim running in a sandbox is sent readable URLs; a human peer reads the store itself. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… staged copy, and one with no readable URL fails before it is sent anything Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…peer reads the store itself No integration test sent an agent a file part. The echo agent now reports what each file part it is sent holds, and answers a `send-file <uri>` line with a file part, so a local run can show: the solver fetches the file in its prompt and a user-sim the one the solver returns, both over grants; a human peer, named by user_a2a_url or registered, is sent the store's own URL and reads it from the store; and the conversation records only the store's own URLs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n sent the target A target's reply is model output, and naming any object a store owns in it made core send the user-sim a URL it could read, and so read the object out through the user-sim's reply. The user-sim is now made able to read only the files the target was sent in this conversation; any other object a store owns is sent as it is, as before this branch. readable_parts and send_and_wait take the objects that may be made readable as `shareable`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
End-to-end and chaos results (final head 855d29b)Setup:
* VM-provider staging fails for the solver and the user-sim alike. Inside the VM, the agent's own public hostname presents a self-signed certificate (confirmed with a probe from the container). So the target path from #57 fails the same way. It's a platform issue, tracked separately. † OpenCode fails its turn when a message carries an ‡ This is Also checked on this head:
Earlier rounds on 8c14a26 (the sharing fix) and e3d556c gave the same results for the cases they covered. |
…le parts; name the test waits Reading file:// paths let anyone who can reach a deployed echo agent read its files, its environment included. The human-peer test now checks the peer is sent the store's own URL without the agent opening it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
| _, reply, peer_reply, _ = _conversation(await task.run()) | ||
|
|
||
| assert _uris(reply) == [urls["report"]] | ||
| assert _text(peer_reply).splitlines()[-1].startswith("could not read report.txt over file:") |
There was a problem hiding this comment.
The human-peer test now expects the peer to fail when reading the file. The test peer no longer opens file:// URLs, so this test can pass even if the URL sent to a human peer points to the wrong file. Keep the test agent's safe reader, but check the sent URL against the store object or use a separate trusted reader to check its contents.
Knowledge Base Used: Storage, objects, documents, and secrets
Prompt To Fix With AI
This is a comment left during a code review.
Path: tst/integration/task_step/test_prompt_agent_file_parts_local.py
Line: 189
Comment:
**Human file reads go untested**
The human-peer test now expects the peer to fail when reading the file. The test peer no longer opens `file://` URLs, so this test can pass even if the URL sent to a human peer points to the wrong file. Keep the test agent's safe reader, but check the sent URL against the store object or use a separate trusted reader to check its contents.
**Knowledge Base Used:** [Storage, objects, documents, and secrets](https://app.greptile.com/scale-ai/-/custom-context/knowledge-base/scaleapi/agentenv-framework/-/docs/storage-and-secrets.md)
---
For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.There was a problem hiding this comment.
Fixed in 8f7cf7e: the in-process peer records the file URIs it is sent, and the test asserts they are exactly the store object's own URL.
…wn URL, not just a file:// one Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nd-helper # Conflicts: # src/agent_env/task_step/task_steps/prompt_agent.py
Summary
prompt_agentsends messages to two peers: the target agent, and the user agent that answers it in a multi-turn conversation. Only the first went throughreadable_parts(#57). The user agent was sent the target agent's reply parts unchanged. So a user-sim agent received a file part naming a store-owned object as the store's raw URL, which it can't read without the store's credentials.Both sends now go through one helper,
send_and_wait, ina2a_agent/object_transfer.py. It sends parts to an A2A peer and polls the task until it ends.readable_parts.prompt_agentcollects the file URIs it sends the target and passes them asshareable. Any other store-owned URI in a reply is sent as it is, as before.user_a2a_urlor a registered human peer with no sandbox, reads the store itself. It is sent the parts as they are, so no signed URL is stored on its side.before_sendruns once the parts are ready, just before the message goes out. The target's turn is still recorded there, so an object the agent can't be sent still leaves no turn waiting for a reply.There are no other message sends to agents with file parts in core: the rubrics judge and the trigger executor send text only.
Tests
Unit (
prompt_agent_file_parts_test.py,readable_parts_test.py):user_a2a_urlhuman peers get the object's own URL;readable_parts(shareable=...)makes only the named objects readable.Integration, new
tst/integration/task_step/test_prompt_agent_file_parts_local.py, fast tier, on real local agents:send-file <uri>with a file part;Before this change there was no integration test that sent an agent a file part.
Mutant checks:
main's code fails the user-sim tests;shareablefails both guard tests.Suite:
tst/unit+ protocol, 6263 passed. CI's integration tiers pass.Plugin API: no break.
End-to-end and chaos results are in a comment below.
🤖 Generated with Claude Code
The PR appears safe to merge; no new issue remains from the changes since the previous review.
Fix with agent prompt
Summary
prompt_agentnow prepares file parts for both deployed agents in a multi-turn conversation. User-sims get readable links only for files the target received, while human peers keep the store’s own URLs.Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR Target[Target reply] --> Check{User peer} Check -->|Sandboxed user-sim| Shared{URI sent to target?} Shared -->|Yes| Readable[Grant or stage readable file] Shared -->|No| Original[Keep original URI] Check -->|Human peer| Original Readable --> Send[Send and wait] Original --> SendReviews (7) · Last reviewed commit: "Merge remote-tracking branch 'origin/mai..."