You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 5ae4dcd
Browse filesBrowse the repository at this point in the historyBrowse files
fix(tools): stop provider timeout params from becoming the request deadline (#8878)
* fix(tools): stop provider timeout params from becoming the request deadline
The request transport and the internal-operation path read params.timeout as a
millisecond deadline for every tool. Twilio make_call, New Relic NRQL, Apify
(3 tools), Daytona (2 tools), and Trigger.dev waitpoint tokens declare their own
timeout param in seconds or as a duration, so a 60-second setting aborted the
call after 60 ms. A declared timeout param is now the deadline only when the tool
sets timeoutParamIsDeadline (http_request, firecrawl_map, firecrawl_parse);
callers can still bound tools that declare none. No param ids change.
Redis and Upstash coerced params with Number() inside tools.config.tool, which
runs at serialization on the serialized params object, turning <Block.output>
references into NaN. The coercions now run in tools.config.params.
Guardrails: check-block-registry rejects coerced assignments to params inside an
inline tools.config.tool; check-tool-param-reachability rejects a method param on
a fixed-verb external tool, which the transport would send as the HTTP verb.
* fix(audits): catch coercions under fallbacks in tools.config.tool, and clarify declared timeout params
* fix(audits): treat every value-deriving expression as a selector coercion
* fix(audits): reject compound assignments and increments on params in selectors
Copy file name to clipboardExpand all lines: .agents/skills/add-tools/SKILL.md
+2Lines changed: 2 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -190,6 +190,8 @@ fallback, or caller-controlled `_context` authority.
190
190
191
191
A required `'hidden'` param needs an `oauth` declaration or `hosting.apiKeyParam` to supply it (`bun run check:tool-param-reachability`).
192
192
193
+
A declared `timeout` param is an ordinary tool input — put it in the request body or URL yourself if the provider expects it; it becomes Sim's millisecond request deadline only when the tool sets `timeoutParamIsDeadline: true` (`http_request`). A `method` param on a tool with a fixed `request.method` would be sent as the HTTP verb, so the same audit rejects it.
0 commit comments