Require ACP adapters to enforce tool-free workflow Agent sessions #496

Description

@taras

Story

As a workflow host, I want every supported ACP adapter to enforce a workflow
Agent session with no native tools, terminal, filesystem client, MCP server, or
direct network access, so the Agent can observe the workflow only through the
XMD operations the host provides.

An ACP adapter is the integration that connects XMD to a coding-Agent provider.

Example outcome

A workflow starts an Agent that may read prompt data and propose constrained
XMD. Inside that session, the Agent has:

  • no terminal or command tool;
  • no filesystem client;
  • no Workspace or host directory as its working directory;
  • no additional directory;
  • no MCP server or MCP tool; and
  • no direct network tool.

Before the first Prompt, the adapter proves that it can establish this complete
mode. If it cannot, XMD refuses the session without executing a Prompt.

The same restriction remains true after loading, resuming, or reconnecting to
the session.

Current boundary

The initial supervised workflow uses a cooperative approximation:

  • no Workspace materialization or ACP additional directories;
  • an empty disposable working directory;
  • no configured MCP servers;
  • an empty allowed-tool list where the adapter supports one;
  • a deny-all permission policy; and
  • an explicit failure when the Agent attempts a native tool.

That profile is sufficient to exercise the workflow without claiming that every
adapter makes tools unavailable. This issue supplies the stronger portable
guarantee.

What counts as enforcement

The workflow host requests one closed no-tool session mode from the provider.
The provider reports whether the selected adapter can enforce every part of that
mode before session creation, resumption, or Prompt execution.

The following do not prove that a tool was unavailable:

  • denying permission after the model selected a tool;
  • asking the model not to use tools in a Prompt;
  • passing an empty tool list when the adapter treats empty as unspecified; or
  • omitting a tool from XMD configuration while the provider supplies it by
    default.

An unsupported adapter fails closed. It does not silently run a broader session.

Provider boundary

Core requests the provider-neutral no-tool mode without depending on ACPX or a
particular adapter type.

Each adapter qualifies by proving its actual session behavior. An ACPX adapter
may require a new embedded-runtime option or capability report, but this issue
does not by itself authorize an upstream issue, dependency pin, or release.

Ordinary caller-selected Agent permissions under xmd run remain unchanged.

Acceptance

  • The provider API can request the complete no-tool workflow mode without
    exposing adapter-specific types to core.
  • Every shipped adapter either proves the complete mode before Prompt or refuses
    the session.
  • Empty allowed tools is distinct from unspecified tool configuration.
  • Tests prove the absence of terminal, filesystem, MCP, working-directory,
    environment, and direct-network capability.
  • The same ceiling survives load, resume, and reconnect.
  • A negative control fails when a tool is merely denied after selection rather
    than made unavailable.
  • Unsupported adapters begin no session and execute no Prompt.
  • Architecture and ACP/workflow specifications distinguish the cooperative
    initial profile from this enforced guarantee.

Delivery relationship

This is independent hardening. It does not retroactively block delivery of the
supervised workflow under its explicitly narrower initial claim.

Out of scope

  • Giving the Agent direct read-only Workspace access.
  • ACP additional directories.
  • Replacing constrained generated-XMD admission.
  • Authorizing upstream ACPX work without a separate decision.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity hardening

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Require ACP adapters to enforce tool-free workflow Agent sessions #496

      Description

      @taras

      Story

      As a workflow host, I want every supported ACP adapter to enforce a workflow
      Agent session with no native tools, terminal, filesystem client, MCP server, or
      direct network access, so the Agent can observe the workflow only through the
      XMD operations the host provides.

      An ACP adapter is the integration that connects XMD to a coding-Agent provider.

      Example outcome

      A workflow starts an Agent that may read prompt data and propose constrained
      XMD. Inside that session, the Agent has:

      • no terminal or command tool;
      • no filesystem client;
      • no Workspace or host directory as its working directory;
      • no additional directory;
      • no MCP server or MCP tool; and
      • no direct network tool.

      Before the first Prompt, the adapter proves that it can establish this complete
      mode. If it cannot, XMD refuses the session without executing a Prompt.

      The same restriction remains true after loading, resuming, or reconnecting to
      the session.

      Current boundary

      The initial supervised workflow uses a cooperative approximation:

      • no Workspace materialization or ACP additional directories;
      • an empty disposable working directory;
      • no configured MCP servers;
      • an empty allowed-tool list where the adapter supports one;
      • a deny-all permission policy; and
      • an explicit failure when the Agent attempts a native tool.

      That profile is sufficient to exercise the workflow without claiming that every
      adapter makes tools unavailable. This issue supplies the stronger portable
      guarantee.

      What counts as enforcement

      The workflow host requests one closed no-tool session mode from the provider.
      The provider reports whether the selected adapter can enforce every part of that
      mode before session creation, resumption, or Prompt execution.

      The following do not prove that a tool was unavailable:

      • denying permission after the model selected a tool;
      • asking the model not to use tools in a Prompt;
      • passing an empty tool list when the adapter treats empty as unspecified; or
      • omitting a tool from XMD configuration while the provider supplies it by
        default.

      An unsupported adapter fails closed. It does not silently run a broader session.

      Provider boundary

      Core requests the provider-neutral no-tool mode without depending on ACPX or a
      particular adapter type.

      Each adapter qualifies by proving its actual session behavior. An ACPX adapter
      may require a new embedded-runtime option or capability report, but this issue
      does not by itself authorize an upstream issue, dependency pin, or release.

      Ordinary caller-selected Agent permissions under xmd run remain unchanged.

      Acceptance

      • The provider API can request the complete no-tool workflow mode without
        exposing adapter-specific types to core.
      • Every shipped adapter either proves the complete mode before Prompt or refuses
        the session.
      • Empty allowed tools is distinct from unspecified tool configuration.
      • Tests prove the absence of terminal, filesystem, MCP, working-directory,
        environment, and direct-network capability.
      • The same ceiling survives load, resume, and reconnect.
      • A negative control fails when a tool is merely denied after selection rather
        than made unavailable.
      • Unsupported adapters begin no session and execute no Prompt.
      • Architecture and ACP/workflow specifications distinguish the cooperative
        initial profile from this enforced guarantee.

      Delivery relationship

      This is independent hardening. It does not retroactively block delivery of the
      supervised workflow under its explicitly narrower initial claim.

      Out of scope

      • Giving the Agent direct read-only Workspace access.
      • ACP additional directories.
      • Replacing constrained generated-XMD admission.
      • Authorizing upstream ACPX work without a separate decision.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        securitySecurity hardening

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Require ACP adapters to enforce tool-free workflow Agent sessions #496

          Description

          @taras

          Story

          As a workflow host, I want every supported ACP adapter to enforce a workflow
          Agent session with no native tools, terminal, filesystem client, MCP server, or
          direct network access, so the Agent can observe the workflow only through the
          XMD operations the host provides.

          An ACP adapter is the integration that connects XMD to a coding-Agent provider.

          Example outcome

          A workflow starts an Agent that may read prompt data and propose constrained
          XMD. Inside that session, the Agent has:

          • no terminal or command tool;
          • no filesystem client;
          • no Workspace or host directory as its working directory;
          • no additional directory;
          • no MCP server or MCP tool; and
          • no direct network tool.

          Before the first Prompt, the adapter proves that it can establish this complete
          mode. If it cannot, XMD refuses the session without executing a Prompt.

          The same restriction remains true after loading, resuming, or reconnecting to
          the session.

          Current boundary

          The initial supervised workflow uses a cooperative approximation:

          • no Workspace materialization or ACP additional directories;
          • an empty disposable working directory;
          • no configured MCP servers;
          • an empty allowed-tool list where the adapter supports one;
          • a deny-all permission policy; and
          • an explicit failure when the Agent attempts a native tool.

          That profile is sufficient to exercise the workflow without claiming that every
          adapter makes tools unavailable. This issue supplies the stronger portable
          guarantee.

          What counts as enforcement

          The workflow host requests one closed no-tool session mode from the provider.
          The provider reports whether the selected adapter can enforce every part of that
          mode before session creation, resumption, or Prompt execution.

          The following do not prove that a tool was unavailable:

          • denying permission after the model selected a tool;
          • asking the model not to use tools in a Prompt;
          • passing an empty tool list when the adapter treats empty as unspecified; or
          • omitting a tool from XMD configuration while the provider supplies it by
            default.

          An unsupported adapter fails closed. It does not silently run a broader session.

          Provider boundary

          Core requests the provider-neutral no-tool mode without depending on ACPX or a
          particular adapter type.

          Each adapter qualifies by proving its actual session behavior. An ACPX adapter
          may require a new embedded-runtime option or capability report, but this issue
          does not by itself authorize an upstream issue, dependency pin, or release.

          Ordinary caller-selected Agent permissions under xmd run remain unchanged.

          Acceptance

          • The provider API can request the complete no-tool workflow mode without
            exposing adapter-specific types to core.
          • Every shipped adapter either proves the complete mode before Prompt or refuses
            the session.
          • Empty allowed tools is distinct from unspecified tool configuration.
          • Tests prove the absence of terminal, filesystem, MCP, working-directory,
            environment, and direct-network capability.
          • The same ceiling survives load, resume, and reconnect.
          • A negative control fails when a tool is merely denied after selection rather
            than made unavailable.
          • Unsupported adapters begin no session and execute no Prompt.
          • Architecture and ACP/workflow specifications distinguish the cooperative
            initial profile from this enforced guarantee.

          Delivery relationship

          This is independent hardening. It does not retroactively block delivery of the
          supervised workflow under its explicitly narrower initial claim.

          Out of scope

          • Giving the Agent direct read-only Workspace access.
          • ACP additional directories.
          • Replacing constrained generated-XMD admission.
          • Authorizing upstream ACPX work without a separate decision.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            securitySecurity hardening

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Require ACP adapters to enforce tool-free workflow Agent sessions #496

              Description

              @taras

              Story

              As a workflow host, I want every supported ACP adapter to enforce a workflow
              Agent session with no native tools, terminal, filesystem client, MCP server, or
              direct network access, so the Agent can observe the workflow only through the
              XMD operations the host provides.

              An ACP adapter is the integration that connects XMD to a coding-Agent provider.

              Example outcome

              A workflow starts an Agent that may read prompt data and propose constrained
              XMD. Inside that session, the Agent has:

              • no terminal or command tool;
              • no filesystem client;
              • no Workspace or host directory as its working directory;
              • no additional directory;
              • no MCP server or MCP tool; and
              • no direct network tool.

              Before the first Prompt, the adapter proves that it can establish this complete
              mode. If it cannot, XMD refuses the session without executing a Prompt.

              The same restriction remains true after loading, resuming, or reconnecting to
              the session.

              Current boundary

              The initial supervised workflow uses a cooperative approximation:

              • no Workspace materialization or ACP additional directories;
              • an empty disposable working directory;
              • no configured MCP servers;
              • an empty allowed-tool list where the adapter supports one;
              • a deny-all permission policy; and
              • an explicit failure when the Agent attempts a native tool.

              That profile is sufficient to exercise the workflow without claiming that every
              adapter makes tools unavailable. This issue supplies the stronger portable
              guarantee.

              What counts as enforcement

              The workflow host requests one closed no-tool session mode from the provider.
              The provider reports whether the selected adapter can enforce every part of that
              mode before session creation, resumption, or Prompt execution.

              The following do not prove that a tool was unavailable:

              • denying permission after the model selected a tool;
              • asking the model not to use tools in a Prompt;
              • passing an empty tool list when the adapter treats empty as unspecified; or
              • omitting a tool from XMD configuration while the provider supplies it by
                default.

              An unsupported adapter fails closed. It does not silently run a broader session.

              Provider boundary

              Core requests the provider-neutral no-tool mode without depending on ACPX or a
              particular adapter type.

              Each adapter qualifies by proving its actual session behavior. An ACPX adapter
              may require a new embedded-runtime option or capability report, but this issue
              does not by itself authorize an upstream issue, dependency pin, or release.

              Ordinary caller-selected Agent permissions under xmd run remain unchanged.

              Acceptance

              • The provider API can request the complete no-tool workflow mode without
                exposing adapter-specific types to core.
              • Every shipped adapter either proves the complete mode before Prompt or refuses
                the session.
              • Empty allowed tools is distinct from unspecified tool configuration.
              • Tests prove the absence of terminal, filesystem, MCP, working-directory,
                environment, and direct-network capability.
              • The same ceiling survives load, resume, and reconnect.
              • A negative control fails when a tool is merely denied after selection rather
                than made unavailable.
              • Unsupported adapters begin no session and execute no Prompt.
              • Architecture and ACP/workflow specifications distinguish the cooperative
                initial profile from this enforced guarantee.

              Delivery relationship

              This is independent hardening. It does not retroactively block delivery of the
              supervised workflow under its explicitly narrower initial claim.

              Out of scope

              • Giving the Agent direct read-only Workspace access.
              • ACP additional directories.
              • Replacing constrained generated-XMD admission.
              • Authorizing upstream ACPX work without a separate decision.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                securitySecurity hardening

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Require ACP adapters to enforce tool-free workflow Agent sessions #496

                  Description

                  @taras

                  Story

                  As a workflow host, I want every supported ACP adapter to enforce a workflow
                  Agent session with no native tools, terminal, filesystem client, MCP server, or
                  direct network access, so the Agent can observe the workflow only through the
                  XMD operations the host provides.

                  An ACP adapter is the integration that connects XMD to a coding-Agent provider.

                  Example outcome

                  A workflow starts an Agent that may read prompt data and propose constrained
                  XMD. Inside that session, the Agent has:

                  • no terminal or command tool;
                  • no filesystem client;
                  • no Workspace or host directory as its working directory;
                  • no additional directory;
                  • no MCP server or MCP tool; and
                  • no direct network tool.

                  Before the first Prompt, the adapter proves that it can establish this complete
                  mode. If it cannot, XMD refuses the session without executing a Prompt.

                  The same restriction remains true after loading, resuming, or reconnecting to
                  the session.

                  Current boundary

                  The initial supervised workflow uses a cooperative approximation:

                  • no Workspace materialization or ACP additional directories;
                  • an empty disposable working directory;
                  • no configured MCP servers;
                  • an empty allowed-tool list where the adapter supports one;
                  • a deny-all permission policy; and
                  • an explicit failure when the Agent attempts a native tool.

                  That profile is sufficient to exercise the workflow without claiming that every
                  adapter makes tools unavailable. This issue supplies the stronger portable
                  guarantee.

                  What counts as enforcement

                  The workflow host requests one closed no-tool session mode from the provider.
                  The provider reports whether the selected adapter can enforce every part of that
                  mode before session creation, resumption, or Prompt execution.

                  The following do not prove that a tool was unavailable:

                  • denying permission after the model selected a tool;
                  • asking the model not to use tools in a Prompt;
                  • passing an empty tool list when the adapter treats empty as unspecified; or
                  • omitting a tool from XMD configuration while the provider supplies it by
                    default.

                  An unsupported adapter fails closed. It does not silently run a broader session.

                  Provider boundary

                  Core requests the provider-neutral no-tool mode without depending on ACPX or a
                  particular adapter type.

                  Each adapter qualifies by proving its actual session behavior. An ACPX adapter
                  may require a new embedded-runtime option or capability report, but this issue
                  does not by itself authorize an upstream issue, dependency pin, or release.

                  Ordinary caller-selected Agent permissions under xmd run remain unchanged.

                  Acceptance

                  • The provider API can request the complete no-tool workflow mode without
                    exposing adapter-specific types to core.
                  • Every shipped adapter either proves the complete mode before Prompt or refuses
                    the session.
                  • Empty allowed tools is distinct from unspecified tool configuration.
                  • Tests prove the absence of terminal, filesystem, MCP, working-directory,
                    environment, and direct-network capability.
                  • The same ceiling survives load, resume, and reconnect.
                  • A negative control fails when a tool is merely denied after selection rather
                    than made unavailable.
                  • Unsupported adapters begin no session and execute no Prompt.
                  • Architecture and ACP/workflow specifications distinguish the cooperative
                    initial profile from this enforced guarantee.

                  Delivery relationship

                  This is independent hardening. It does not retroactively block delivery of the
                  supervised workflow under its explicitly narrower initial claim.

                  Out of scope

                  • Giving the Agent direct read-only Workspace access.
                  • ACP additional directories.
                  • Replacing constrained generated-XMD admission.
                  • Authorizing upstream ACPX work without a separate decision.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    securitySecurity hardening

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Require ACP adapters to enforce tool-free workflow Agent sessions #496

                      Description

                      @taras

                      Story

                      As a workflow host, I want every supported ACP adapter to enforce a workflow
                      Agent session with no native tools, terminal, filesystem client, MCP server, or
                      direct network access, so the Agent can observe the workflow only through the
                      XMD operations the host provides.

                      An ACP adapter is the integration that connects XMD to a coding-Agent provider.

                      Example outcome

                      A workflow starts an Agent that may read prompt data and propose constrained
                      XMD. Inside that session, the Agent has:

                      • no terminal or command tool;
                      • no filesystem client;
                      • no Workspace or host directory as its working directory;
                      • no additional directory;
                      • no MCP server or MCP tool; and
                      • no direct network tool.

                      Before the first Prompt, the adapter proves that it can establish this complete
                      mode. If it cannot, XMD refuses the session without executing a Prompt.

                      The same restriction remains true after loading, resuming, or reconnecting to
                      the session.

                      Current boundary

                      The initial supervised workflow uses a cooperative approximation:

                      • no Workspace materialization or ACP additional directories;
                      • an empty disposable working directory;
                      • no configured MCP servers;
                      • an empty allowed-tool list where the adapter supports one;
                      • a deny-all permission policy; and
                      • an explicit failure when the Agent attempts a native tool.

                      That profile is sufficient to exercise the workflow without claiming that every
                      adapter makes tools unavailable. This issue supplies the stronger portable
                      guarantee.

                      What counts as enforcement

                      The workflow host requests one closed no-tool session mode from the provider.
                      The provider reports whether the selected adapter can enforce every part of that
                      mode before session creation, resumption, or Prompt execution.

                      The following do not prove that a tool was unavailable:

                      • denying permission after the model selected a tool;
                      • asking the model not to use tools in a Prompt;
                      • passing an empty tool list when the adapter treats empty as unspecified; or
                      • omitting a tool from XMD configuration while the provider supplies it by
                        default.

                      An unsupported adapter fails closed. It does not silently run a broader session.

                      Provider boundary

                      Core requests the provider-neutral no-tool mode without depending on ACPX or a
                      particular adapter type.

                      Each adapter qualifies by proving its actual session behavior. An ACPX adapter
                      may require a new embedded-runtime option or capability report, but this issue
                      does not by itself authorize an upstream issue, dependency pin, or release.

                      Ordinary caller-selected Agent permissions under xmd run remain unchanged.

                      Acceptance

                      • The provider API can request the complete no-tool workflow mode without
                        exposing adapter-specific types to core.
                      • Every shipped adapter either proves the complete mode before Prompt or refuses
                        the session.
                      • Empty allowed tools is distinct from unspecified tool configuration.
                      • Tests prove the absence of terminal, filesystem, MCP, working-directory,
                        environment, and direct-network capability.
                      • The same ceiling survives load, resume, and reconnect.
                      • A negative control fails when a tool is merely denied after selection rather
                        than made unavailable.
                      • Unsupported adapters begin no session and execute no Prompt.
                      • Architecture and ACP/workflow specifications distinguish the cooperative
                        initial profile from this enforced guarantee.

                      Delivery relationship

                      This is independent hardening. It does not retroactively block delivery of the
                      supervised workflow under its explicitly narrower initial claim.

                      Out of scope

                      • Giving the Agent direct read-only Workspace access.
                      • ACP additional directories.
                      • Replacing constrained generated-XMD admission.
                      • Authorizing upstream ACPX work without a separate decision.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        securitySecurity hardening

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Require ACP adapters to enforce tool-free workflow Agent sessions #496

                          Description

                          @taras

                          Story

                          As a workflow host, I want every supported ACP adapter to enforce a workflow
                          Agent session with no native tools, terminal, filesystem client, MCP server, or
                          direct network access, so the Agent can observe the workflow only through the
                          XMD operations the host provides.

                          An ACP adapter is the integration that connects XMD to a coding-Agent provider.

                          Example outcome

                          A workflow starts an Agent that may read prompt data and propose constrained
                          XMD. Inside that session, the Agent has:

                          • no terminal or command tool;
                          • no filesystem client;
                          • no Workspace or host directory as its working directory;
                          • no additional directory;
                          • no MCP server or MCP tool; and
                          • no direct network tool.

                          Before the first Prompt, the adapter proves that it can establish this complete
                          mode. If it cannot, XMD refuses the session without executing a Prompt.

                          The same restriction remains true after loading, resuming, or reconnecting to
                          the session.

                          Current boundary

                          The initial supervised workflow uses a cooperative approximation:

                          • no Workspace materialization or ACP additional directories;
                          • an empty disposable working directory;
                          • no configured MCP servers;
                          • an empty allowed-tool list where the adapter supports one;
                          • a deny-all permission policy; and
                          • an explicit failure when the Agent attempts a native tool.

                          That profile is sufficient to exercise the workflow without claiming that every
                          adapter makes tools unavailable. This issue supplies the stronger portable
                          guarantee.

                          What counts as enforcement

                          The workflow host requests one closed no-tool session mode from the provider.
                          The provider reports whether the selected adapter can enforce every part of that
                          mode before session creation, resumption, or Prompt execution.

                          The following do not prove that a tool was unavailable:

                          • denying permission after the model selected a tool;
                          • asking the model not to use tools in a Prompt;
                          • passing an empty tool list when the adapter treats empty as unspecified; or
                          • omitting a tool from XMD configuration while the provider supplies it by
                            default.

                          An unsupported adapter fails closed. It does not silently run a broader session.

                          Provider boundary

                          Core requests the provider-neutral no-tool mode without depending on ACPX or a
                          particular adapter type.

                          Each adapter qualifies by proving its actual session behavior. An ACPX adapter
                          may require a new embedded-runtime option or capability report, but this issue
                          does not by itself authorize an upstream issue, dependency pin, or release.

                          Ordinary caller-selected Agent permissions under xmd run remain unchanged.

                          Acceptance

                          • The provider API can request the complete no-tool workflow mode without
                            exposing adapter-specific types to core.
                          • Every shipped adapter either proves the complete mode before Prompt or refuses
                            the session.
                          • Empty allowed tools is distinct from unspecified tool configuration.
                          • Tests prove the absence of terminal, filesystem, MCP, working-directory,
                            environment, and direct-network capability.
                          • The same ceiling survives load, resume, and reconnect.
                          • A negative control fails when a tool is merely denied after selection rather
                            than made unavailable.
                          • Unsupported adapters begin no session and execute no Prompt.
                          • Architecture and ACP/workflow specifications distinguish the cooperative
                            initial profile from this enforced guarantee.

                          Delivery relationship

                          This is independent hardening. It does not retroactively block delivery of the
                          supervised workflow under its explicitly narrower initial claim.

                          Out of scope

                          • Giving the Agent direct read-only Workspace access.
                          • ACP additional directories.
                          • Replacing constrained generated-XMD admission.
                          • Authorizing upstream ACPX work without a separate decision.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            securitySecurity hardening

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Require ACP adapters to enforce tool-free workflow Agent sessions #496

                              Description

                              @taras

                              Story

                              As a workflow host, I want every supported ACP adapter to enforce a workflow
                              Agent session with no native tools, terminal, filesystem client, MCP server, or
                              direct network access, so the Agent can observe the workflow only through the
                              XMD operations the host provides.

                              An ACP adapter is the integration that connects XMD to a coding-Agent provider.

                              Example outcome

                              A workflow starts an Agent that may read prompt data and propose constrained
                              XMD. Inside that session, the Agent has:

                              • no terminal or command tool;
                              • no filesystem client;
                              • no Workspace or host directory as its working directory;
                              • no additional directory;
                              • no MCP server or MCP tool; and
                              • no direct network tool.

                              Before the first Prompt, the adapter proves that it can establish this complete
                              mode. If it cannot, XMD refuses the session without executing a Prompt.

                              The same restriction remains true after loading, resuming, or reconnecting to
                              the session.

                              Current boundary

                              The initial supervised workflow uses a cooperative approximation:

                              • no Workspace materialization or ACP additional directories;
                              • an empty disposable working directory;
                              • no configured MCP servers;
                              • an empty allowed-tool list where the adapter supports one;
                              • a deny-all permission policy; and
                              • an explicit failure when the Agent attempts a native tool.

                              That profile is sufficient to exercise the workflow without claiming that every
                              adapter makes tools unavailable. This issue supplies the stronger portable
                              guarantee.

                              What counts as enforcement

                              The workflow host requests one closed no-tool session mode from the provider.
                              The provider reports whether the selected adapter can enforce every part of that
                              mode before session creation, resumption, or Prompt execution.

                              The following do not prove that a tool was unavailable:

                              • denying permission after the model selected a tool;
                              • asking the model not to use tools in a Prompt;
                              • passing an empty tool list when the adapter treats empty as unspecified; or
                              • omitting a tool from XMD configuration while the provider supplies it by
                                default.

                              An unsupported adapter fails closed. It does not silently run a broader session.

                              Provider boundary

                              Core requests the provider-neutral no-tool mode without depending on ACPX or a
                              particular adapter type.

                              Each adapter qualifies by proving its actual session behavior. An ACPX adapter
                              may require a new embedded-runtime option or capability report, but this issue
                              does not by itself authorize an upstream issue, dependency pin, or release.

                              Ordinary caller-selected Agent permissions under xmd run remain unchanged.

                              Acceptance

                              • The provider API can request the complete no-tool workflow mode without
                                exposing adapter-specific types to core.
                              • Every shipped adapter either proves the complete mode before Prompt or refuses
                                the session.
                              • Empty allowed tools is distinct from unspecified tool configuration.
                              • Tests prove the absence of terminal, filesystem, MCP, working-directory,
                                environment, and direct-network capability.
                              • The same ceiling survives load, resume, and reconnect.
                              • A negative control fails when a tool is merely denied after selection rather
                                than made unavailable.
                              • Unsupported adapters begin no session and execute no Prompt.
                              • Architecture and ACP/workflow specifications distinguish the cooperative
                                initial profile from this enforced guarantee.

                              Delivery relationship

                              This is independent hardening. It does not retroactively block delivery of the
                              supervised workflow under its explicitly narrower initial claim.

                              Out of scope

                              • Giving the Agent direct read-only Workspace access.
                              • ACP additional directories.
                              • Replacing constrained generated-XMD admission.
                              • Authorizing upstream ACPX work without a separate decision.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                securitySecurity hardening

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions