Repository navigation
Mask secrets in common.ai tool results before they reach the model - #73897
Merged
Merged
Conversation
kaxil
added this pull request to stack #73905
September 29, 2026 12:49
kaxil
marked this pull request as ready for review
September 29, 2026 13:17
kaxil
requested review from
Lee-W,
amoghrajesh,
ashb,
bugraoz93,
gopidesupavan,
jason810496,
jscheffl and
potiuk
as code owners
September 29, 2026 13:17
kaxil
force-pushed
the
commonai-mask-tool-results
branch
from
September 29, 2026 14:03
e096343 to
672de6c
Compare
vatsrahul1001
approved these changes
Sep 30, 2026
The SQL, hook, DataFusion, MCP, sandbox and managed-agent toolsets now pass what they return, and any exception they raise, through Airflow's secret masker. A connection password that shows up in a database error or a hook's return value previously went to the model, its provider and traces as is. Structured results are masked before they are serialized, since JSON escaping would hide a secret containing a quote, backslash or non-ASCII character from the masker. An exception keeps its type, but its message is masked and its cause chain is dropped; pydantic-ai's approval and deferral signals pass through as control flow. AgentOperator also masks the output of the toolsets passed in toolsets, in agent_params["toolsets"] and in a Toolset capability, including toolsets the Dag author wrote. Blocking hook calls now run in a worker thread, one at a time per process, instead of on the event loop.
kaxil
force-pushed
the
commonai-mask-tool-results
branch
from
September 30, 2026 06:01
672de6c to
9b75369
Compare
Lee-W
reviewed
Sep 30, 2026
Lee-W
reviewed
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A connection password that shows up in a database error or a hook's return value reached the model, the model provider and any trace unmasked: the task log masks it, but tool results and the error text handed back to the model did not pass through the masker. The SQL, hook, DataFusion, MCP, sandbox and managed-agent toolsets now pass what they return, and any exception they raise, through Airflow's secret masker, and
AgentOperatorwraps every other toolset it runs, including toolsets the Dag author wrote.OSErrorfields and whatever a custom__str__reads are masked too; if the message still holds a secret, aRuntimeErrorcarrying the masked message takes its place.Only secrets Airflow has registered are masked, such as connection passwords and sensitive connection extras. Prompts and model output are not tool output and are not masked; the agent security page says so.
An
AgentOperatorrun against a real Claude model. The connection password, the API keys and the token in a file all reach the model as***:{pr_number}.significant.rst, in airflow-core/newsfragments. You can add this file in a follow-up commit after the PR is created so you know the PR number.