AE Agent Errors
AE-9V72XDR6

Workspace execute_command tool sends model-chosen commands to the host shell with no approval gate by default on an un-isolated local sandbox

AUTHORITY ERRORseverity: HIGHcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: LOW

With a Workspace using the built-in LocalSandbox at its default isolation 'none', the auto-exposed execute_command tool resolved requireApproval to false, so a single model-driven tool call, including one induced by untrusted content, reached the host shell without human approval. The report frames it as a fail-safe-default hardening issue rather than an observed incident.

Framework / agent
Mastra (@mastra/core) · tool-calling agent with a workspace sandbox
Remediation attempts
TESTED
Recurrence
not documented
Source languages
en
Updated
2026-09-30

Sources

Symptoms

  • execute_command resolves to requireApproval: false and the command is dispatched to the host shell without an approval prompt
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-9V72XDR6. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.