mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-07 02:59:05 +00:00
security: gate litellm_skills proxy hook behind LITELLM_ENABLE_SKILLS env var
The SkillsInjectionHook auto-registers in PROXY_HOOKS and executes model-generated Python code via SkillsSandboxExecutor without human confirmation. This makes the hook opt-in only by requiring LITELLM_ENABLE_SKILLS=true to be set explicitly.
This commit is contained in:
parent
600d7b4a20
commit
0c81cd5a18
1 changed files with 3 additions and 1 deletions
|
|
@ -24,7 +24,6 @@ PROXY_HOOKS = {
|
|||
"parallel_request_limiter": _PROXY_MaxParallelRequestsHandler_v3,
|
||||
"cache_control_check": _PROXY_CacheControlCheck,
|
||||
"responses_id_security": ResponsesIDSecurity,
|
||||
"litellm_skills": SkillsInjectionHook,
|
||||
"max_iterations_limiter": _PROXY_MaxIterationsHandler,
|
||||
"max_budget_per_session_limiter": _PROXY_MaxBudgetPerSessionHandler,
|
||||
}
|
||||
|
|
@ -33,6 +32,9 @@ PROXY_HOOKS = {
|
|||
if os.getenv("LEGACY_MULTI_INSTANCE_RATE_LIMITING", "false").lower() == "true":
|
||||
PROXY_HOOKS["parallel_request_limiter"] = _PROXY_MaxParallelRequestsHandler
|
||||
|
||||
if os.getenv("LITELLM_ENABLE_SKILLS", "false").lower() == "true":
|
||||
PROXY_HOOKS["litellm_skills"] = SkillsInjectionHook
|
||||
|
||||
|
||||
### update PROXY_HOOKS with ENTERPRISE_PROXY_HOOKS ###
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue