Theodore LiandClaude Opus 5 8348592d38 fix(copilot): close fail-open write gates in agent tools (#6132)
* fix(copilot): make tool write gates fail closed

The three handler-map management tools (manage_custom_tool,
manage_mcp_tool, manage_skill) gated writes with
`context.userPermission && perm !== 'write' && perm !== 'admin'`.
userPermission is optional on the execution context, so an absent value
skipped the check entirely and the write proceeded unguarded — while
the server-tool router's equivalent gate is fail-closed. Both paths now
share copilotToolCanWrite, built on the canonical permissionSatisfies
(null/undefined never satisfies).

manage_custom_tool additionally resolved its target as
`params.workspaceId || context.workspaceId`, so a model-supplied
workspace id won while the permission check was resolved for the
context workspace — and upsertCustomTools performs no authz of its own.
It now uses the server-set context only, matching its two siblings.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CiHhAk2R1NryaS3R8n2yFz

* fix(copilot): gate materialize_file writes and enforce the deploy mutation lock

materialize_file's save/extract/import all create workspace resources, but
the handler-map path has no central permission check, so a read-only member
could create files and workflows through the agent. Gate on write access
after param validation.

assertWorkflowMutable moves into performFullDeploy / performFullUndeploy /
performActivateVersion, where performRevertToVersion already had it. The
check previously lived only in the deploy routes, so the copilot deploy
tools — which call the orchestration functions directly — could deploy,
undeploy, and activate versions of a locked workflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(copilot): enforce secret-admin on env writes and gate KB indexing on usage

Two more paths where the agent is a weaker route to the same write than the UI.

upsertWorkspaceEnvVars was a weakened copy of the environment route's write:
no per-key secret-admin check, no advisory lock, no audit row. Its only caller
is the set_environment_variables copilot tool, which gates on workspace 'write'
alone — so any write-level member could have the agent overwrite a workspace
secret they do not administer, with nothing in the audit log and a lost-update
race against the route's locked transaction. The gate now lives in the function
so every caller inherits it, reusing getWorkspaceEnvKeyAdminAccess rather than
restating the route's logic.

knowledge_base add_file computed a billing attribution and then indexed without
calling checkAttributedUsageLimits, which every upload route applies before
accepting indexing work — an over-quota workspace could index without limit
through the agent. The same file's query operation already gated correctly.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(copilot): return lock denials and stop bootstrapping a legacy secret's ACL

Two defects in the previous commits, both found by review.

assertWorkflowMutable throws, and the three orchestration entry points awaited
it outside any try/catch, so a locked workflow escaped as an exception instead
of the { success: false } result the callers consume — performChatDeploy and
the copilot deploy tools would have surfaced a generic 500 rather than a lock
denial. performRevertToVersion already converted it; the three now do too,
through a shared helper.

upsertWorkspaceEnvVars derived newKeys for createWorkspaceEnvCredentials from
the credential rows rather than the stored variables. A secret written before
credential rows existed has no ACL, so overwriting it looked like adding a new
key: it minted a credential and made the caller that secret's admin. The
environment route derives newKeys from the locked jsonb read for exactly this
reason, and now so does this.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* style(env): collapse the merged test import onto one line

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PCXbU36FwJBmtJKaH83BUm

* fix(env): give the workspace env denial its own write-access message

WorkspaceEnvAccessError reported "must be an admin of these secrets" for
both denials, so a caller lacking workspace write to ADD a key was told to
get secret-admin on a key that does not exist yet. Carry the reason and
mirror the route's two messages.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PCXbU36FwJBmtJKaH83BUm

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-01 21:01:45 -04:00

Sim.ai Documentation Slack X

Ask DeepWiki Set Up with Cursor

Sim — Integrate, Context, Build, and Monitor AI agents

A workspace to build, deploy and manage AI agents and workflows.

Quickstart

Cloud-hosted: sim.ai

Open sim.ai

Self-hosted

git clone https://github.com/simstudioai/sim.git && cd sim
bun run setup

Open http://localhost:3000

The Sim platform — chat on the left, the visual workflow builder on the right

Capabilities

  • Connect 1,000+ integrations and every major LLM
  • Add Slack, Notion, HubSpot, Salesforce, databases, and more
  • Build agents visually, conversationally, or with code
  • Ingest files, knowledge bases, and structured table data
  • Monitor runs, logs, schedules, and workflow activity

One workspace, every surface

Chat and workflows are just the start — tables, files, knowledge, and scheduled tasks all live in the same workspace.

Tables in Sim — structured data your agents can query

Tables — a database, built in

Files in Sim — documents for your team and every agent

Files — one store for your team and every agent

Knowledge bases in Sim — synced docs your agents can search

Knowledge — your agents' memory

Scheduled tasks in Sim — recurring agent runs on a calendar

Scheduled tasks — runs on your schedule

Self-hosting

Requirements: Bun and Docker.

bun run setup is an interactive wizard: it provisions the database, generates secrets, writes your .env files, connects a Chat API key, and starts Sim the way you choose:

  • Local dev — run from source to contribute or hack on Sim
  • Docker Compose — a self-contained instance for testing self-hosting
  • Kubernetes (Helm) — deploy to a local cluster

When it finishes, open http://localhost:3000.

Manage your install with bun run sim:

bun run sim start | stop | restart   # bring your install up / down / cycle
bun run sim status                    # what's installed and healthy
bun run sim logs                      # follow logs
bun run sim doctor                    # diagnose configuration problems
bun run sim down                      # remove containers (data kept)
bun run sim reset                     # archive .env and wipe managed data

sim detects how you're running (Docker Compose, local dev, or Kubernetes) and acts accordingly.

Prefer a bare sim? Run bun link once — but note sim lands in ~/.bun/bin, which Homebrew's bun doesn't add to your PATH, so you may need export PATH="$HOME/.bun/bin:$PATH" in your shell profile.

Sim also supports local models via Ollama and vLLM. See the self-hosting docs for details.

Chat API Keys

Chat is a Sim-managed service. bun run setup connects a Chat API key for you — sign in when it opens your browser and the key is stored automatically. To view, create, or revoke keys later, go to sim.ai/selfhost/settings/chat-keys.

Environment Variables

See the environment variables reference for the full list, or apps/sim/.env.example for defaults.

Tech Stack

Next.js · Bun · PostgreSQL · Drizzle · Better Auth · Tailwind — and the rest of the stack

Contributing

We welcome contributions! Please see our Contributing Guide for details.

License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.

Built by the Sim team in San Francisco

Languages
TypeScript 77%
MDX 20.8%
JavaScript 1.9%
CSS 0.1%