New:Socket for Asana Is Now Available.Learn more
Get Started

@mcoda/codali

Package Overview
Dependencies
Maintainers
1
Versions
55
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@mcoda/codali - npm Package Compare versions

Comparing version
0.1.123
to
0.1.124
+1
-1
dist/gateway/LocalGatewayTaskRunner.d.ts.map

@@ -1,1 +0,1 @@

{"version":3,"file":"LocalGatewayTaskRunner.d.ts","sourceRoot":"","sources":["../../src/gateway/LocalGatewayTaskRunner.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,EACV,QAAQ,EAGT,MAAM,+BAA+B,CAAC;AACvC,OAAO,KAAK,EAAE,YAAY,EAAE,MAAM,0BAA0B,CAAC;AAC7D,OAAO,KAAK,EAAE,WAAW,EAAE,MAAM,uBAAuB,CAAC;AAGzD,OAAO,KAAK,EAEV,+BAA+B,EAC/B,gCAAgC,EAChC,6BAA6B,EAE9B,MAAM,0BAA0B,CAAC;AAElC;;;;;;;;;;;;;;;;;;;;;;;;;;;;GA4BG;AAEH,8EAA8E;AAC9E,eAAO,MAAM,uBAAuB,IAAI,CAAC;AAEzC,2EAA2E;AAC3E,eAAO,MAAM,wBAAwB,IAAI,CAAC;AAe1C,MAAM,WAAW,6BAA6B;IAC5C,QAAQ,EAAE,QAAQ,CAAC;IACnB,QAAQ,EAAE,YAAY,CAAC;IACvB,WAAW,EAAE,WAAW,CAAC;IACzB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,+CAA+C;IAC/C,OAAO,CAAC,EAAE,CAAC,KAAK,EAAE,2BAA2B,KAAK,IAAI,CAAC;CACxD;AAED,MAAM,MAAM,2BAA2B,GACnC;IAAE,IAAI,EAAE,YAAY,CAAC;IAAC,MAAM,EAAE,MAAM,CAAC;IAAC,UAAU,EAAE,MAAM,CAAC;IAAC,YAAY,EAAE,MAAM,EAAE,CAAA;CAAE,GAClF;IAAE,IAAI,EAAE,WAAW,CAAC;IAAC,MAAM,EAAE,MAAM,CAAC;IAAC,IAAI,EAAE,MAAM,CAAC;IAAC,IAAI,EAAE,OAAO,CAAA;CAAE,GAClE;IACE,IAAI,EAAE,aAAa,CAAC;IACpB,MAAM,EAAE,MAAM,CAAC;IACf,IAAI,EAAE,MAAM,CAAC;IACb,EAAE,EAAE,OAAO,CAAC;IACZ,SAAS,EAAE,MAAM,CAAC;IAClB,SAAS,CAAC,EAAE,MAAM,CAAC;CACpB,GACD;IACE,IAAI,EAAE,UAAU,CAAC;IACjB,MAAM,EAAE,MAAM,CAAC;IACf,MAAM,EAAE,WAAW,GAAG,QAAQ,CAAC;IAC/B,aAAa,EAAE,MAAM,CAAC;IACtB,cAAc,EAAE,MAAM,CAAC;IACvB,UAAU,EAAE,MAAM,CAAC;CACpB,CAAC;AAsEN,qBAAa,sBAAuB,YAAW,6BAA6B;IAC9D,OAAO,CAAC,QAAQ,CAAC,OAAO;gBAAP,OAAO,EAAE,6BAA6B;IAE7D,GAAG,CACP,KAAK,EAAE,+BAA+B,GACrC,OAAO,CAAC,gCAAgC,CAAC;CAqT7C;AAED,eAAO,MAAM,4BAA4B,GACvC,SAAS,6BAA6B,KACrC,sBAA6D,CAAC;AAEjE,eAAO,MAAM,aAAa,UApYD,OAAO,KAAG,KAAK,IAAI,MAAM,CAAC,MAAM,EAAE,OAAO,CAoY7B,CAAC"}
{"version":3,"file":"LocalGatewayTaskRunner.d.ts","sourceRoot":"","sources":["../../src/gateway/LocalGatewayTaskRunner.ts"],"names":[],"mappings":"AAAA,OAAO,KAAK,EACV,QAAQ,EAGT,MAAM,+BAA+B,CAAC;AACvC,OAAO,KAAK,EAAE,YAAY,EAAE,MAAM,0BAA0B,CAAC;AAC7D,OAAO,KAAK,EAAE,WAAW,EAAE,MAAM,uBAAuB,CAAC;AAGzD,OAAO,KAAK,EAEV,+BAA+B,EAC/B,gCAAgC,EAChC,6BAA6B,EAE9B,MAAM,0BAA0B,CAAC;AAElC;;;;;;;;;;;;;;;;;;;;;;;;;;;;GA4BG;AAEH,8EAA8E;AAC9E,eAAO,MAAM,uBAAuB,IAAI,CAAC;AAEzC,2EAA2E;AAC3E,eAAO,MAAM,wBAAwB,IAAI,CAAC;AAe1C,MAAM,WAAW,6BAA6B;IAC5C,QAAQ,EAAE,QAAQ,CAAC;IACnB,QAAQ,EAAE,YAAY,CAAC;IACvB,WAAW,EAAE,WAAW,CAAC;IACzB,SAAS,CAAC,EAAE,MAAM,CAAC;IACnB,WAAW,CAAC,EAAE,MAAM,CAAC;IACrB,+CAA+C;IAC/C,OAAO,CAAC,EAAE,CAAC,KAAK,EAAE,2BAA2B,KAAK,IAAI,CAAC;CACxD;AAED,MAAM,MAAM,2BAA2B,GACnC;IAAE,IAAI,EAAE,YAAY,CAAC;IAAC,MAAM,EAAE,MAAM,CAAC;IAAC,UAAU,EAAE,MAAM,CAAC;IAAC,YAAY,EAAE,MAAM,EAAE,CAAA;CAAE,GAClF;IAAE,IAAI,EAAE,WAAW,CAAC;IAAC,MAAM,EAAE,MAAM,CAAC;IAAC,IAAI,EAAE,MAAM,CAAC;IAAC,IAAI,EAAE,OAAO,CAAA;CAAE,GAClE;IACE,IAAI,EAAE,aAAa,CAAC;IACpB,MAAM,EAAE,MAAM,CAAC;IACf,IAAI,EAAE,MAAM,CAAC;IACb,EAAE,EAAE,OAAO,CAAC;IACZ,SAAS,EAAE,MAAM,CAAC;IAClB,SAAS,CAAC,EAAE,MAAM,CAAC;CACpB,GACD;IACE,IAAI,EAAE,UAAU,CAAC;IACjB,MAAM,EAAE,MAAM,CAAC;IACf,MAAM,EAAE,WAAW,GAAG,QAAQ,CAAC;IAC/B,aAAa,EAAE,MAAM,CAAC;IACtB,cAAc,EAAE,MAAM,CAAC;IACvB,UAAU,EAAE,MAAM,CAAC;CACpB,CAAC;AAuGN,qBAAa,sBAAuB,YAAW,6BAA6B;IAC9D,OAAO,CAAC,QAAQ,CAAC,OAAO;gBAAP,OAAO,EAAE,6BAA6B;IAE7D,GAAG,CACP,KAAK,EAAE,+BAA+B,GACrC,OAAO,CAAC,gCAAgC,CAAC;CA2U7C;AAED,eAAO,MAAM,4BAA4B,GACvC,SAAS,6BAA6B,KACrC,sBAA6D,CAAC;AAEjE,eAAO,MAAM,aAAa,UA3bD,OAAO,KAAG,KAAK,IAAI,MAAM,CAAC,MAAM,EAAE,OAAO,CA2b7B,CAAC"}

@@ -68,2 +68,30 @@ import { truncateToolResult } from "../tools/TruncateResult.js";

}));
/**
* Markers of a model describing tool activity that never happened.
*
* A worker offered tools and asked for evidence will sometimes write what a
* successful transcript looks like instead of calling anything — tool names,
* call ids, `"status": "success"`, and rows of data underneath. Observed in a
* timesheet product: employee ids and hours that exist nowhere, carrying a
* `tool_call_id` and labelled successful, against a connector that received no
* request at all.
*
* Prose is not the problem. A worker may legitimately answer "the results do
* not cover this" without calling anything. What must never pass is a claim of
* execution, because the evidence normalizer reads structures like
* `evidence_items` and would take invented rows for retrieved ones.
*/
const FABRICATED_TOOL_RESULT_MARKERS = [
/"?tool_call_id"?\s*[:=]/i,
/"?evidence_items"?\s*[:=]/i,
/"?raw_data_excerpt"?\s*[:=]/i,
/"?tool_name"?\s*[:=]/i,
/"?status"?\s*[:=]\s*"?success"?/i,
];
const claimsToolExecution = (output) => {
if (!output)
return false;
// Two independent markers, so a passing mention of a tool name is not enough.
return FABRICATED_TOOL_RESULT_MARKERS.filter((marker) => marker.test(output)).length >= 2;
};
const buildTaskMessages = (input, hasTools) => {

@@ -83,2 +111,6 @@ const system = [

"Prefer several complementary calls over one broad one — unused calls cost nothing, a missing one costs the answer.",
// A worker asked for evidence has been observed writing what a
// successful transcript looks like — call ids, statuses and rows of
// invented data — instead of calling anything.
"Never describe a tool result you did not receive. If you call nothing, say what you could not determine; do not write out call ids, statuses, or example rows as though a tool had returned them.",
].join("\n")

@@ -184,2 +216,20 @@ : "No tools are available. Answer from the task description alone or state what is missing.",

const output = selection.message.content.trim();
// A worker that was given tools, called none, and then described tool
// results has invented them. Passing that on as a successful task makes
// fabricated rows indistinguishable from retrieved ones by the time the
// normalizer sees them, so it fails here instead.
if (toolDefinitions.length > 0 && claimsToolExecution(output)) {
return finish({
status: "failed",
errorCode: "GATEWAY_WORKER_FABRICATED_TOOL_RESULT",
errorMessage: "The worker reported tool results without calling any tool. Its output has been " +
"discarded rather than treated as evidence.",
metadata: {
pass: "direct",
modelCallCount: modelCalls.length,
toolCallCount: 0,
fabricatedToolResult: true,
},
});
}
return finish({

@@ -192,2 +242,5 @@ status: "succeeded",

toolCallCount: 0,
// Nothing was retrieved, so nothing downstream may treat this as
// having been.
...(toolDefinitions.length > 0 ? { noToolsExecuted: true } : {}),
...(droppedForBudget > 0 ? { droppedToolCalls: droppedForBudget } : {}),

@@ -194,0 +247,0 @@ },

{
"name": "@mcoda/codali",
"version": "0.1.123",
"version": "0.1.124",
"description": "Standalone tool-runner adapter for mcoda.",

@@ -38,4 +38,4 @@ "type": "module",

"@modelcontextprotocol/sdk": "1.30.0",
"@mcoda/db": "0.1.123",
"@mcoda/shared": "0.1.123"
"@mcoda/db": "0.1.124",
"@mcoda/shared": "0.1.124"
},

@@ -42,0 +42,0 @@ "scripts": {