Skip to content

Mask secrets in common.ai tool results before they reach the model - #73897

Merged
kaxil merged 1 commit into
mainfrom
commonai-mask-tool-results
Sep 30, 2026
Merged

kaxil merged 1 commit into
mainfrom
commonai-mask-tool-results

Conversation

@kaxil

@kaxil kaxil commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

A connection password that shows up in a database error or a hook's return value reached the model, the model provider and any trace unmasked: the task log masks it, but tool results and the error text handed back to the model did not pass through the masker. The SQL, hook, DataFusion, MCP, sandbox and managed-agent toolsets now pass what they return, and any exception they raise, through Airflow's secret masker, and AgentOperator wraps every other toolset it runs, including toolsets the Dag author wrote.

  • Structured results are masked before they are serialized. JSON escapes quotes, backslashes and non-ASCII characters, so a password containing any of them no longer matches the registered value once it is inside a JSON string.
  • An exception keeps its type but loses its cause chain. Frameworks and tracing record a failed call's traceback, cause included, so the original is logged to the (masked) task log and the chain is dropped. A retry rule can still match the exception's type. OSError fields and whatever a custom __str__ reads are masked too; if the message still holds a secret, a RuntimeError carrying the masked message takes its place.
  • Blocking hook calls run in a worker thread, one at a time per process. Agent frameworks run tool calls concurrently, and before Airflow 3.2 the channel to the supervisor that resolves connections and variables has no lock of its own.

Only secrets Airflow has registered are masked, such as connection passwords and sensitive connection extras. Prompts and model output are not tool output and are not masked; the agent security page says so.

An AgentOperator run against a real Claude model. The connection password, the API keys and the token in a file all reach the model as ***:

AgentOperator log with masked tool results


  • Read the Pull Request Guidelines for more information. Note: commit author/co-author name and email in commits become permanently public when merged.
  • For fundamental code changes, an Airflow Improvement Proposal (AIP) is needed.
  • When adding dependency, check compliance with the ASF 3rd Party License Policy.
  • For significant user-facing changes create newsfragment: {pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.

@kaxil
kaxil added this pull request to stack #73905 September 29, 2026 12:49
@kaxil kaxil closed this Sep 29, 2026
@kaxil kaxil reopened this Sep 29, 2026
@kaxil
kaxil marked this pull request as ready for review September 29, 2026 13:17
Base automatically changed from commonai-stability-page to main September 29, 2026 14:02
@kaxil
kaxil force-pushed the commonai-mask-tool-results branch from e096343 to 672de6c Compare September 29, 2026 14:03
The SQL, hook, DataFusion, MCP, sandbox and managed-agent toolsets now
pass what they return, and any exception they raise, through Airflow's
secret masker. A connection password that shows up in a database error
or a hook's return value previously went to the model, its provider and
traces as is. Structured results are masked before they are serialized,
since JSON escaping would hide a secret containing a quote, backslash or
non-ASCII character from the masker. An exception keeps its type, but its
message is masked and its cause chain is dropped; pydantic-ai's approval
and deferral signals pass through as control flow. AgentOperator also
masks the output of the toolsets passed in toolsets, in
agent_params["toolsets"] and in a Toolset capability, including toolsets
the Dag author wrote.

Blocking hook calls now run in a worker thread, one at a time per
process, instead of on the event loop.
@kaxil
kaxil force-pushed the commonai-mask-tool-results branch from 672de6c to 9b75369 Compare September 30, 2026 06:01
@kaxil
kaxil merged commit 023f859 into main Sep 30, 2026
36 checks passed
@kaxil
kaxil deleted the commonai-mask-tool-results branch September 30, 2026 06:04
Comment thread providers/common/ai/src/airflow/providers/common/ai/toolsets/mcp.py
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants