Skip to content

[aw-daily] GAP-004: Document cache-memory working-tree sanitization in tools-reference.md #28

@zircote

Description

@zircote

Gap Details

Type: missing
File: skills/aw-author/references/tools-reference.md
Section: Built-in MCP Tools — Cache Memory (cache-memory:) section

Current Content

The cache-memory: section documents configuration options but does not mention the pre-agent working-tree sanitization behavior.

Expected Content

Add a behavior note after the configuration table:

**Pre-agent working-tree sanitization:** Before the agent job starts, `cache-memory` automatically scans the restored cache for planted executables and disallowed file types. Any neutralized files are reported in the workflow logs. This protects against cache-poisoning attacks where a malicious actor could insert executable files into the cache between runs.

Source

PR #26587 in github/gh-aw: cache-memory: add pre-agent working-tree sanitization to neutralize planted executables and disallowed files

Intelligence Report

#24


Automated by /aw-daily on 2026-04-16

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions