Repository navigation
Conversation
A recipe is a list of agent-browser argv steps ending in an eval that
returns a JSON object, with typed params, an origins allowlist, and verify
rules. All of it is pure and lives in @tyto/core.
- parseRecipe validates structure (kebab name, origins, typed params,
last step eval, verify, regression).
- lintRecipe enforces the security rules: command allowlist, no {{…}}
inside eval code, no @en snapshot refs, open URLs inside origins,
read-only eval heuristics, no password/token/OTP/card fills, no
:nth-of-type built from a param.
- renderRecipe resolves defaults and types, applies lower/underscore/
path/url filters, refuses values that would become flags or leave the
origins, and wraps eval code so it reads params from a JSON literal
(proven in a sandbox against quotes, backslashes, and </script>).
- verifyResult checks required fields and regex matches with params
escaped, comparing non-strings JSON-style.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #5. Spec sentences from
docs/IMPLEMENTATION.md§4 Slice 2.What
All in
packages/core/src/recipe/(pure, no I/O):parseRecipe: structural validation. Covers kebab-case name,version: 1, draft/approved status,auth, the origins list (https://host[:port]), typed params (string/int/enum, with checked defaults), steps as argv arrays ending in["eval", code],verifyandregression.lintRecipe: the security rules.cookies,storage,network,download,upload,auth,state,snapshotandscreenshotare rejected.{{…}}inside eval code.@eNsnapshot refs.openURLs must stay insideorigins.fetch, XHR,sendBeacon, WebSocket,import(,document.cookie, local/session storage,locationassignment/assign/replace,window.open,.submit(.:nth-of-typebuilt from a param.renderRecipe:lower/underscore/path/urlfilters;-, and URLs outsideorigins(includinggithub.com.evil.test);(function(params){ return eval(code) })(JSON.parse(...))and base64-encodes it, so values are never pasted into code.verifyResult: required fields, regexmatchwith params regex-escaped, non-string values compared JSON-style, and a miss when the result isn't a JSON object.The eval-wrapping test runs the rendered code in
node:vmwith a param containing quotes, backslashes, backticks,${}and</script>, and checks the round trip.Tests
npm run check: 4 files, 35 tests (22 new), import boundary clean, secret scan clean, typecheck clean.🤖 Generated with Claude Code