mirror of
https://github.com/usestrix/strix.git
synced 2026-08-20 18:38:57 +02:00
The custom ``Capability`` subclass was 207 LoC bundling four tiny concerns (env-var injection, tool exposure, system-prompt block, healthcheck) — and three of them were dead code: the SDK's ``SandboxRunConfig`` doesn't accept capabilities, so ``process_manifest``, ``tools()``, and ``instructions()`` were never called. Only ``bind()`` ran, because we invoked it manually. Replace each piece with the obvious direct equivalent: - **Env vars**: inject ``http_proxy`` / ``https_proxy`` / ``ALL_PROXY`` directly into the manifest in ``session_manager.create_or_reuse``. This *also fixes a latent bug* — the proxy env vars in ``CaidoCapability.process_manifest`` weren't being applied to live containers, so shelled-out HTTP traffic from terminal/python tools wasn't actually flowing through Caido. - **Tool exposure**: add the seven Caido tools (``list_requests``, ``view_request``, ``send_request``, ``repeat_request``, ``scope_rules``, ``list_sitemap``, ``view_sitemap_entry``) to ``_BASE_TOOLS`` in ``agents/factory.py`` like every other sandbox tool. They were already defined in ``tools/proxy/tools.py``. - **Healthcheck**: ``entry.py`` now ``await``s ``wait_for_http_ready`` + ``wait_for_tcp_ready`` inline after ``session_manager.create_or_reuse`` returns, before any agent runs. No more capability state, ``configure_host_ports`` plumbing, or ``on_agent_start`` await-the-task indirection. - **Instructions block**: dropped. The seven proxy tools' docstrings cover the HTTPQL syntax and usage already; the duplicate prompt fragment was overhead. Cascade cleanups: - Drop ``caido_capability`` from the agent context (was passed to every ``make_agent_context`` call but only used by the now-deleted ``on_agent_start`` await). - Strip the capability await branch from ``StrixOrchestrationHooks.on_agent_start``; that hook now does only the ``tracer.agents`` mirroring it always should have. - Drop the ``capability`` key from the session bundle. - Drop ``strix/sandbox/caido_capability.py`` — entire file (207 LoC). - Drop the per-file ruff ignore for the deleted file. mypy clean on every touched file. Net -217 LoC.
220 lines
6.6 KiB
Python
220 lines
6.6 KiB
Python
"""``build_strix_agent`` — assemble an ``agents.Agent`` for root or child.
|
|
|
|
Wires the SDK function tools, multi-agent graph tools, and the rendered
|
|
Jinja prompt into one ``agents.Agent`` ready for ``Runner.run``.
|
|
|
|
Two flavors:
|
|
|
|
- **Root** (``is_root=True``): top-level scan agent. Carries
|
|
``finish_scan`` and stops there.
|
|
- **Child** (``is_root=False``): subagents spawned by the
|
|
``create_agent`` graph tool. Carries ``agent_finish`` and stops
|
|
there — without ``stop_at_tool_names`` the SDK loop would keep
|
|
running to ``max_turns`` even after the child reported back.
|
|
|
|
Skills are baked into the system prompt at scan bring-up; there's no
|
|
runtime skill-loading tool.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from typing import Any
|
|
|
|
from agents import Agent
|
|
from agents.agent import StopAtTools
|
|
from agents.tool import Tool
|
|
|
|
from strix.agents.prompt import render_system_prompt
|
|
from strix.tools.agents_graph.tools import (
|
|
agent_finish,
|
|
agent_status,
|
|
create_agent,
|
|
send_message_to_agent,
|
|
view_agent_graph,
|
|
wait_for_message,
|
|
)
|
|
from strix.tools.browser.tool import browser_action
|
|
from strix.tools.file_edit.tools import (
|
|
list_files,
|
|
search_files,
|
|
str_replace_editor,
|
|
)
|
|
from strix.tools.finish.tool import finish_scan
|
|
from strix.tools.notes.tools import (
|
|
create_note,
|
|
delete_note,
|
|
get_note,
|
|
list_notes,
|
|
update_note,
|
|
)
|
|
from strix.tools.proxy.tools import (
|
|
list_requests,
|
|
list_sitemap,
|
|
repeat_request,
|
|
scope_rules,
|
|
send_request,
|
|
view_request,
|
|
view_sitemap_entry,
|
|
)
|
|
from strix.tools.python.tool import python_action
|
|
from strix.tools.reporting.tool import create_vulnerability_report
|
|
from strix.tools.terminal.tool import terminal_execute
|
|
from strix.tools.thinking.tool import think
|
|
from strix.tools.todo.tools import (
|
|
create_todo,
|
|
delete_todo,
|
|
list_todos,
|
|
mark_todo_done,
|
|
mark_todo_pending,
|
|
update_todo,
|
|
)
|
|
from strix.tools.web_search.tool import web_search
|
|
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
# Tools every Strix agent has, root or child.
|
|
_BASE_TOOLS: tuple[Tool, ...] = (
|
|
# Thinking + planning
|
|
think,
|
|
# Per-agent todos
|
|
create_todo,
|
|
list_todos,
|
|
update_todo,
|
|
mark_todo_done,
|
|
mark_todo_pending,
|
|
delete_todo,
|
|
# Shared notes (per-run JSONL store)
|
|
create_note,
|
|
list_notes,
|
|
get_note,
|
|
update_note,
|
|
delete_note,
|
|
# Web search (only registered if PERPLEXITY_API_KEY is set; the
|
|
# tool itself returns a structured error when not configured, so
|
|
# always exposing it is safe)
|
|
web_search,
|
|
# File edit (sandbox-bound)
|
|
str_replace_editor,
|
|
list_files,
|
|
search_files,
|
|
# Reporting
|
|
create_vulnerability_report,
|
|
# Sandbox primitives
|
|
browser_action,
|
|
terminal_execute,
|
|
python_action,
|
|
# Caido HTTP/HTTPS proxy
|
|
list_requests,
|
|
view_request,
|
|
send_request,
|
|
repeat_request,
|
|
scope_rules,
|
|
list_sitemap,
|
|
view_sitemap_entry,
|
|
# Multi-agent graph tools (the bus is in ctx.context)
|
|
view_agent_graph,
|
|
agent_status,
|
|
send_message_to_agent,
|
|
wait_for_message,
|
|
create_agent,
|
|
)
|
|
|
|
|
|
def build_strix_agent(
|
|
*,
|
|
name: str = "strix",
|
|
skills: list[str] | None = None,
|
|
is_root: bool,
|
|
scan_mode: str = "deep",
|
|
is_whitebox: bool = False,
|
|
interactive: bool = False,
|
|
system_prompt_context: dict[str, Any] | None = None,
|
|
) -> Agent[Any]:
|
|
"""Build an ``agents.Agent`` configured for either root or child use.
|
|
|
|
Args:
|
|
name: Agent name. Surfaces in traces and the bus's ``names`` map.
|
|
Defaults to ``"strix"`` for the root; create_agent passes
|
|
distinct names per child.
|
|
skills: Skills to preload into the system prompt.
|
|
is_root: Selects the tool list and ``tool_use_behavior``.
|
|
Root carries ``finish_scan`` and stops there; child carries
|
|
``agent_finish`` and stops there.
|
|
scan_mode: ``"deep"`` etc.; routes the scan-mode skill section
|
|
of the prompt template.
|
|
is_whitebox: Whitebox source-aware mode toggle. Adds two extra
|
|
skills to the prompt and gates whitebox-only behavior in
|
|
the create_agent / wiki integration.
|
|
interactive: Renders the interactive-mode communication block
|
|
in the system prompt.
|
|
system_prompt_context: Free-form dict the prompt template
|
|
renders into the ``system_prompt_context`` variable —
|
|
today carries the scan scope / authorization block.
|
|
|
|
Returns the ``Agent`` instance with ``model=None`` so the
|
|
``RunConfig.model`` (built by ``make_run_config``) drives provider
|
|
selection. ``agents.Agent`` is generic on context type; we let
|
|
the caller's ``Runner.run(context=...)`` typing determine that.
|
|
"""
|
|
instructions = render_system_prompt(
|
|
skills=skills,
|
|
scan_mode=scan_mode,
|
|
is_whitebox=is_whitebox,
|
|
interactive=interactive,
|
|
system_prompt_context=system_prompt_context,
|
|
)
|
|
|
|
# Tool list + termination tool depend on is_root. The tuple-then-
|
|
# list dance keeps _BASE_TOOLS immutable so concurrent agent builds
|
|
# can't accidentally mutate each other's tool list.
|
|
if is_root:
|
|
tools: list[Tool] = [*_BASE_TOOLS, finish_scan]
|
|
stop_at = ("finish_scan",)
|
|
else:
|
|
tools = [*_BASE_TOOLS, agent_finish]
|
|
stop_at = ("agent_finish",)
|
|
|
|
return Agent(
|
|
name=name,
|
|
instructions=instructions,
|
|
tools=tools,
|
|
tool_use_behavior=StopAtTools(stop_at_tool_names=list(stop_at)),
|
|
# model=None so ``RunConfig.model`` drives provider selection
|
|
# via :func:`build_multi_provider` rather than the SDK's default.
|
|
model=None,
|
|
)
|
|
|
|
|
|
def make_child_factory(
|
|
*,
|
|
scan_mode: str = "deep",
|
|
is_whitebox: bool = False,
|
|
interactive: bool = False,
|
|
system_prompt_context: dict[str, Any] | None = None,
|
|
) -> Any:
|
|
"""Return a callable suitable for ``ctx.context['agent_factory']``.
|
|
|
|
The ``create_agent`` graph tool reads
|
|
``ctx.context['agent_factory']`` and calls it with ``name=`` and
|
|
``skills=`` to build a child ``Agent``. Run-level arguments
|
|
(``scan_mode``, ``is_whitebox``, etc.) are captured in a closure so
|
|
each child inherits the scan-level configuration without
|
|
``create_agent`` having to know about them.
|
|
"""
|
|
|
|
def _factory(*, name: str, skills: list[str]) -> Agent[Any]:
|
|
return build_strix_agent(
|
|
name=name,
|
|
skills=skills,
|
|
is_root=False,
|
|
scan_mode=scan_mode,
|
|
is_whitebox=is_whitebox,
|
|
interactive=interactive,
|
|
system_prompt_context=system_prompt_context,
|
|
)
|
|
|
|
return _factory
|