fix: python_eval — os.makedirs/mkdir 허용(폴더 생성은 파괴 연산 아님) + 파일 다운로드 가이드 설명 삽입

SO-101 워크숍 채팅(ws_proj_1osbd78g)에서 폴더 생성이 차단돼 STL 다운로드 작업이 죽고,
모델이 차단을 '권한 문제'로 오독해 파일 수령을 포기하는 실측 사례 수정.
- BLOCKED에서 makedirs/mkdir 분리 — remove/rename/rmtree 등 파괴 연산은 계속 차단
- python_eval 설명에 다운로드 가이드 인접 삽입: GitHub API로 경로 먼저 확인,
  받은 개수 실측 보고, 기대보다 적으면 실패로 보고

Co-Authored-By: Claude Code <noreply@anthropic.com>
This commit is contained in:
kim
2026-09-23 13:03:53 +09:00
co-authored by Claude Code
parent a815721976
commit f89b61f15f
2 changed files with 7 additions and 3 deletions
+1 -1
View File
@@ -1358,7 +1358,7 @@ export function createBuildTools(isOrchestrationSkillEnabled: () => boolean) {
type: 'function',
function: {
name: 'python_eval',
description: 'Execute Python code in the workspace directory. Returns stdout/stderr. Useful for math, data analysis, CSV/JSON processing.',
description: 'Execute Python code in the workspace directory. Returns stdout/stderr. Useful for math, data analysis, CSV/JSON processing, and scripting tasks. 폴더 생성(os.makedirs)은 허용됨(삭제·이름변경만 차단). 웹에서 파일 내려받기: urllib.request/requests로 raw.githubusercontent.com 등의 직접 URL에서 받고, 받은 파일 개수를 실제로 세어 보고할 것 — 기대 개수보다 적으면 성공이 아니라 실패. GitHub 저장소 파일은 추측 경로 대신 GitHub API로 먼저 확인: https://api.github.com/repos/{owner}/{repo}/git/trees/{branch}?recursive=1',
parameters: {
type: 'object', required: ['code'],
properties: {
+6 -2
View File
@@ -19,10 +19,14 @@ function getWorkspacePath(args?: any): string {
// os.system / subprocess allow arbitrary shell — not allowed.
// socket / urllib / requests would still work for reading; only server-creation
// and raw socket misuse would need further restrictions if desired.
// 2026-09-23: makedirs/mkdir을 차단에서 제외 — 폴더 "생성"은 파괴 연산이 아니고, 워크숍
// 채팅에서 STL 다운로드용 폴더를 못 만들어 작업이 죽는 실측 사례(ws_proj_1osbd78g, SO-101).
// 모델은 차단을 "권한 문제"로 오독해 파일 수령을 포기했음. remove/rename 등 파괴 연산은
// 계속 차단.
const BLOCKED: RegExp[] = [
/\bos\s*\.\s*system\s*\(/,
/\bsubprocess\s*\.\s*(run|Popen|call|check_output|check_call|getoutput|getstatusoutput)\s*\(/,
/\bos\s*\.\s*(remove|unlink|rmdir|removedirs|rename|replace|makedirs|mkdir)\s*\(/,
/\bos\s*\.\s*(remove|unlink|rmdir|removedirs|rename|replace)\s*\(/,
/\bshutil\s*\.\s*(rmtree|move|copy2?|copytree)\s*\(/,
/\b__import__\s*\(/,
/\bimportlib\s*\.\s*import_module\s*\(/,
@@ -30,7 +34,7 @@ const BLOCKED: RegExp[] = [
export const pythonEvalTool = {
name: 'python_eval',
description: 'Execute Python code and return stdout/stderr. Runs in the workspace directory. Useful for math, data analysis, CSV/JSON processing, and scripting tasks. Standard library and installed packages (numpy, pandas, etc.) are available.',
description: 'Execute Python code and return stdout/stderr. Runs in the workspace directory. Useful for math, data analysis, CSV/JSON processing, and scripting tasks. Standard library and installed packages (numpy, pandas, etc.) are available. 폴더 생성(os.makedirs)은 허용됨(삭제·이름변경만 차단). 웹에서 파일 내려받기: urllib.request/requests로 raw.githubusercontent.com 등의 직접 URL에서 받고, 받은 파일 개수를 실제로 세어 보고할 것 — 기대 개수보다 적으면 성공이 아니라 실패. GitHub 저장소 파일은 추측 경로 대신 GitHub API로 먼저 확인: https://api.github.com/repos/{owner}/{repo}/git/trees/{branch}?recursive=1',
schema: {
code: 'Python code to execute',
timeout: 'Execution timeout in seconds (default: 15, max: 60)',