分类器判断是否允许 — 返回 True=允许 注意 tool_history 只包含工具调用,不包含助手文本。 这是防止社会工程攻击的关键设计。
(
self,
tool_name: str,
tool_input: str,
tool_history: List[Dict],
)
| 643 | return restored |
| 644 | |
| 645 | def classify( |
| 646 | self, |
| 647 | tool_name: str, |
| 648 | tool_input: str, |
| 649 | tool_history: List[Dict], |
| 650 | ) -> bool: |
| 651 | """分类器判断是否允许 — 返回 True=允许 |
| 652 | |
| 653 | 注意 tool_history 只包含工具调用,不包含助手文本。 |
| 654 | 这是防止社会工程攻击的关键设计。 |
| 655 | """ |
| 656 | # 快速路径: 安全工具 |
| 657 | if tool_name in self.SAFE_TOOLS: |
| 658 | return True |
| 659 | |
| 660 | # 模拟两阶段 AI 分类 |
| 661 | # 真实实现中会调用 LLM API |
| 662 | print(f" [YOLO 阶段1] 快速分类: {tool_name}({tool_input[:50]}...)") |
| 663 | phase1_allow = self._phase1_classify(tool_name, tool_input, tool_history) |
| 664 | |
| 665 | if phase1_allow: |
| 666 | return True |
| 667 | |
| 668 | # 阶段 2: 深思 |
| 669 | print(f" [YOLO 阶段2] 深度分类: {tool_name}") |
| 670 | return self._phase2_classify(tool_name, tool_input, tool_history) |
| 671 | |
| 672 | def _phase1_classify(self, tool_name, tool_input, history) -> bool: |
| 673 | """阶段 1: 快速分类 (max_tokens=64)""" |
no test coverage detected