9router/open-sse/executors/antigravity-competitor-strip.check.mjs
Hermes ab66269155 fix(antigravity): strip any competitor system prompt, not one literal
Google answers a systemInstruction advertising a rival agent with 429 RESOURCE_EXHAUSTED - a content refusal shaped like a quota error, which is why it survived the endpoint and backoff fixes. Upstream PR #3223 stripped a single Zed literal, so Claude Code / Hermes wording still tripped it. Match the sentence shape instead. Check fails on the old one-literal code and passes here.
2026-08-25 07:39:21 -04:00

57 lines
2.2 KiB
JavaScript

/**
* #3223-generalised: Antigravity answers a system prompt that advertises a rival
* agent with 429 RESOURCE_EXHAUSTED. Upstream stripped one Zed literal; every
* other client wording still tripped it. This pins the shapes we must strip.
*
* Run: node open-sse/executors/antigravity-competitor-strip.check.mjs
*/
import assert from 'node:assert/strict';
import { readFileSync } from 'node:fs';
import { dirname, resolve } from 'node:path';
import { fileURLToPath } from 'node:url';
import vm from 'node:vm';
const here = dirname(fileURLToPath(import.meta.url));
const src = readFileSync(
process.env.AG_SOURCE || resolve(here, 'antigravity.js'),
'utf8'
);
// Lift the strip block out of buildRequest and run it against a fake request.
const start = src.indexOf('if (requestWithoutTools.systemInstruction?.parts)');
assert.ok(start >= 0, 'competitor-strip block must exist');
const end = src.indexOf('\n }\n', src.indexOf('for (const part', start)) + 6;
const block = src.slice(start, end);
const strip = (text) => {
const requestWithoutTools = { systemInstruction: { parts: [{ text }] } };
vm.runInNewContext(block, { requestWithoutTools });
return requestWithoutTools.systemInstruction.parts[0].text;
};
// The literal upstream already handled — must keep working.
assert.ok(
!strip("You are a Claude agent, built on Anthropic's Claude Agent SDK. Be terse.")
.includes('Claude'),
'Zed wording must still be stripped'
);
// The wordings upstream missed.
for (const prompt of [
"You are Claude Code, Anthropic's official CLI for Claude. Help the user.",
'You are Claude, made by Anthropic!',
'you are a claude agent. lowercase should not save it.',
]) {
const out = strip(prompt);
assert.ok(!/claude/i.test(out), `must strip competitor branding from: ${prompt}`);
}
// Must not eat an innocent prompt.
const benign = 'You are a helpful assistant. Answer in French.';
assert.equal(strip(benign), benign, 'benign prompts must pass through untouched');
// Non-string parts must not throw.
const req = { systemInstruction: { parts: [{ inlineData: {} }] } };
vm.runInNewContext(block, { requestWithoutTools: req });
console.log('antigravity-competitor-strip: all passed');