From b68fdf6d57edee77bcd0b20d141eb78c594328cd Mon Sep 17 00:00:00 2001 From: m4 Date: Wed, 19 Aug 2026 21:59:38 +0800 Subject: [PATCH] feat: disable agent observation writes in web deploy Co-Authored-By: Claude Opus 4.7 --- EvoScientist/EvoScientist.py | 3 +++ tests/test_profile_memory_middleware.py | 17 +++++++++++++++++ 2 files changed, 20 insertions(+) diff --git a/EvoScientist/EvoScientist.py b/EvoScientist/EvoScientist.py index ca038c5..9462fda 100644 --- a/EvoScientist/EvoScientist.py +++ b/EvoScientist/EvoScientist.py @@ -952,6 +952,9 @@ def _get_default_agent(): cfg = _ensure_config() web_full = os.environ.get("EVOSCIENTIST_DEPLOY_MODE", "").lower() == "full" if web_full: + from .config.settings import MemoryObservationWriter + + cfg.memory_observation_writer = MemoryObservationWriter.OFF # Refuse to expose a Web graph whose command isolation is missing or # ineffective. CLI/stripped runtimes do not enter this path. from .native_sandbox import ensure_native_sandbox_ready diff --git a/tests/test_profile_memory_middleware.py b/tests/test_profile_memory_middleware.py index 49452ea..4bcde1b 100644 --- a/tests/test_profile_memory_middleware.py +++ b/tests/test_profile_memory_middleware.py @@ -645,3 +645,20 @@ def test_read_profile_memory_honors_memory_dir_override(tmp_path, monkeypatch): content = middleware._read_profile_memory(memory_dir=user_mem) assert "per-user marker" in content + + +def test_web_full_agent_does_not_expose_record_observation(monkeypatch): + import EvoScientist.EvoScientist as mod + from EvoScientist.config.settings import MemoryObservationWriter + + cfg = mod._ensure_config() + cfg.memory_observation_writer = MemoryObservationWriter.OFF + + mw = mod._get_default_middleware( + workspace_dir="/workspace", + cfg=cfg, + enable_memory_workers=False, + ) + memory_mw = next(m for m in mw if isinstance(m, memory_module.EvoMemoryMiddleware)) + assert "record_observation" not in {t.name for t in memory_mw.tools} + assert {"search_observations", "read_memory"} <= {t.name for t in memory_mw.tools}