fix(spawn): separate preset validation from agent ID allowlist check

Preset names (scout, analyst, etc.) were being sent through the agent ID
allowlist checker, causing all preset-based spawns to be rejected with
"not allowed to spawn agent". Now presets are validated via IsValidPreset()
and only agent_id goes through the allowlist.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
dj-oyu 2026-02-25 15:50:27 +09:00
parent e588b8539f
commit 5b724c4021

View file

@ -80,17 +80,20 @@ func (t *SpawnTool) Execute(ctx context.Context, args map[string]any) *ToolResul
agentID, _ := args["agent_id"].(string)
preset, _ := args["preset"].(string)
// Check allowlist if targeting a specific agent or preset
checkTarget := agentID
if checkTarget == "" && preset != "" {
checkTarget = preset
}
if checkTarget != "" && t.allowlistCheck != nil {
if !t.allowlistCheck(checkTarget) {
return ErrorResult(fmt.Sprintf("preset %q is not allowed. Available presets: scout, analyst, coder, worker, coordinator", preset))
// Check allowlist if targeting a specific agent ID.
// Presets (scout, analyst, etc.) are NOT agent IDs — they are validated
// separately by IsValidPreset() in the subagent manager.
if agentID != "" && t.allowlistCheck != nil {
if !t.allowlistCheck(agentID) {
return ErrorResult(fmt.Sprintf("agent %q is not in the allowed agents list", agentID))
}
}
// Validate preset name if provided
if preset != "" && !IsValidPreset(Preset(preset)) {
return ErrorResult(fmt.Sprintf("preset %q is not valid. Available presets: scout, analyst, coder, worker, coordinator", preset))
}
if t.manager == nil {
return ErrorResult("spawn tool is not available in this session (orchestration may be disabled)")
}