(input: {
readonly integration: string;
readonly slug: string;
readonly clientId: string;
readonly tokenUrl: string;
})
| 93 | // the boundary does with the excess field (drop or reject), the secret VALUE |
| 94 | // must not appear anywhere in the agent-visible result. |
| 95 | const smuggleSecretCode = (input: { |
| 96 | readonly integration: string; |
| 97 | readonly slug: string; |
| 98 | readonly clientId: string; |
| 99 | readonly tokenUrl: string; |
| 100 | }) => ` |
| 101 | const handoff = await tools.executor.coreTools.oauth.clients.createHandoff({ |
| 102 | integration: ${JSON.stringify(input.integration)}, |
| 103 | slug: ${JSON.stringify(input.slug)}, |
| 104 | grant: "client_credentials", |
| 105 | clientId: ${JSON.stringify(input.clientId)}, |
| 106 | tokenUrl: ${JSON.stringify(input.tokenUrl)}, |
| 107 | clientSecret: ${JSON.stringify(SMUGGLED_SECRET)}, |
| 108 | }); |
| 109 | return JSON.stringify(handoff); |
| 110 | `; |
| 111 | |
| 112 | scenario( |
| 113 | "OAuth client · createHandoff returns a secret-free deep link and is not approval-gated", |
no outgoing calls
no test coverage detected