93de5ca4f8
- Fix path traversal in _glob_search by validating resolved paths stay within workspace root - Fix ReDoS vulnerability in _grep_search by adding regex compilation error handling - Replace 6 assert statements with explicit validation (assertions are disabled with -O flag) - Replace bare except Exception with specific exception types (OSError, KeyError, ValueError) - Block file:// scheme in web_fetch to prevent SSRF attacks - Filter sensitive environment variables from subprocess execution - Update test to verify file:// scheme rejection Agent-Logs-Url: https://github.com/HarnessLab/claw-code-agent/sessions/94dfb41f-57dd-48ea-ab0d-d2f2249ef950 Co-authored-by: abdoelsayed2016 <27821589+abdoelsayed2016@users.noreply.github.com>