CodeCall implements bank-grade security through a defense-in-depth architecture. Every script passes through five security layers before execution, ensuring that even if one layer is bypassed, others catch malicious behavior.
100+ Attack Vectors Blocked
Pre-Scanner + AST Guard blocks ReDoS, BiDi attacks, eval, prototype pollution, and more
Layer 0 Defense
Pre-Scanner catches attacks BEFORE parser execution - blocks parser-level DoS
Zero Trust Runtime
Enclave sandbox with whitelist-only globals and resource limits
Security Pipeline
Every script goes through this 5-layer pipeline:Layer 0: Pre-Scanner (Defense-in-Depth)
The Pre-Scanner is a new security layer that runs BEFORE the JavaScript parser (acorn). It provides defense-in-depth protection against attacks that could DoS or exploit the parser itself.Why Layer 0?
Traditional security scanners operate on the AST (Abstract Syntax Tree), which means they rely on the parser completing successfully. Sophisticated attackers can exploit this by:- Parser DoS: Deeply nested brackets/braces can cause stack overflow in recursive descent parsers
- ReDoS at Parse Time: Complex regex literals can hang the parser
- Memory Exhaustion: Large inputs can exhaust memory before validation
- Trojan Source Attacks: Unicode BiDi characters can make code appear different from how it executes
Mandatory Limits (Cannot Be Disabled)
These limits are enforced regardless of configuration:Pre-Scanner Attacks Blocked
ReDoS (Regular Expression Denial of Service)
ReDoS (Regular Expression Denial of Service)
Blocked Patterns:
(a+)+- Nested quantifiers(a|a)+- Overlapping alternation(.*a)+- Greedy backtracking(a+){2,}- Star in repetition
BiDi/Trojan Source Attacks
BiDi/Trojan Source Attacks
Blocked Characters:
- U+202E (Right-to-Left Override)
- U+2066 (Left-to-Right Isolate)
- U+2069 (Pop Directional Isolate)
Parser Stack Overflow
Parser Stack Overflow
Blocked:
- Deeply nested brackets:
(((((((((x))))))))) - Deeply nested braces:
{{{{{{{{{}}}}}}}}}
Input Size DoS
Input Size DoS
Blocked:
- Inputs > 50KB (AgentScript preset)
- Inputs > configured maxInputSize
Null Byte Injection
Null Byte Injection
Blocked:
\x00characters anywhere in input
Pre-Scanner Configuration
CodeCall uses the AgentScript preset which provides the strictest pre-scanning:Layer 1: AST Validation
AST Guard parses JavaScript into an Abstract Syntax Tree and validates every node against security rules before any code executes.Blocked Constructs
Code Execution Attacks
Code Execution Attacks
Blocked:
eval('malicious code')- Dynamic code executionnew Function('return process')()- Function constructorsetTimeout(() => {}, 0)- Timer-based executionsetInterval,setImmediate- Async execution escape
Global/System Access
Global/System Access
Blocked:
process.env.SECRET- Node.js process accessrequire('fs')- Module loadingwindow.location- Browser globalsglobal,globalThis- Global object accessthis- Context leakage
Prototype Pollution
Prototype Pollution
Blocked:
obj.__proto__ = {}- Direct prototype manipulationobj.constructor.prototype- Indirect prototype accessObject.prototype.polluted = true- Global prototype pollution
Unicode/Trojan Source Attacks
Unicode/Trojan Source Attacks
Blocked:
- Bidirectional override characters (CVE-2021-42574)
- Homoglyph attacks (Cyrillic ‘a’ vs Latin ‘a’)
- Zero-width characters
- Invisible formatting characters
Resource Exhaustion
Resource Exhaustion
Blocked:
while (true) {}- Unbounded while loopsdo {} while (true)- Unbounded do-while loopsfor (key in obj)- Prototype chain walking- Recursive function definitions
AgentScript Preset
CodeCall uses the AgentScript preset - the most restrictive preset designed for LLM-generated code: The AgentScript preset enforces these rules:What’s Allowed
Layer 2: Code Transformation
After AST validation passes, code is transformed for safe execution:Transformations Applied
Example
Reserved Prefixes
User code cannot declare identifiers with these prefixes:__ag_- AgentScript internal functions__safe_- Safe runtime proxies
Layer 3: Runtime Sandbox
Enclave executes transformed code in an isolated Node.jsvm context.
Isolation Guarantees
Fresh Context
Each execution gets a new, isolated context with no access to the host environment
Controlled Globals
Only whitelisted globals available: Math, JSON, Array, Object, etc.
No Module Access
No require, import, or dynamic module loading
No Async Escape
No setTimeout, setInterval, or Promise.race tricks
Resource Limits
VM Presets
VM presets control runtime limits (timeout, max steps, max tool calls, console output budget). The full preset reference and Enclave Security Level mapping live in the Configuration page → VM Presets section. Usepreset: 'secure' for production unless you have a specific reason to deviate.
Self-Reference Guard
Critical Security Feature: Scripts cannot call CodeCall meta-tools from within scripts.Why This Matters
Without self-reference blocking, an attacker could:- Recursive execution:
codecall:executecalls itself infinitely - Sandbox escape: Nest executions to accumulate privileges
- Resource exhaustion: Each nested call multiplies resource usage
- Audit bypass: Hide malicious calls in nested scripts
Implementation
The guard runs before any other security checks:Tool Access Control
Beyond the Self-Reference Guard, CodeCall controls which tools scripts can invoke through two configuration options.includeTools Filter
TheincludeTools option on CodeCallPlugin.init() filters which tools are available to CodeCall at the global level:
Direct Invoke Allowlist
For thecodecall:invoke meta-tool, restrict which tools can be called directly:
Per-Tool Metadata
Individual tools opt in or out via thecodecall metadata field:
Default Blocked Patterns
Internally, theToolAccessControlService blocks these patterns by default:
system:*- System administration toolsinternal:*- Internal/private tools__*- Internal implementation toolscodecall:*- Self-reference (via the Self-Reference Guard)
Layer 4: Output Sanitization
All outputs are sanitized before returning to the client through two mechanisms: Value Sanitization (structure/content) and Stack Trace Sanitization (information leakage).Value Sanitization Rules
What Gets Stripped
Value sanitization removes potentially dangerous content:Type Handling
The sanitizer handles special JavaScript types safely:Circular Reference Detection
Information Leakage Prevention (Stack Trace Sanitization)
File System Paths Redacted:
Package Manager Paths Redacted:
Cloud/Container Paths Redacted:
CI/CD Paths Redacted:
- GitHub Actions:
/runner/,/_work/ - GitLab CI:
/builds/, CI variables - Jenkins:
/var/jenkins/, workspace paths - CircleCI:
/circleci/, project paths
- Internal hostnames:
*.internal,*.local - Private IPs:
10.x.x.x,192.168.x.x,172.16-31.x.x - Service URLs: Internal load balancers, databases
Example: Before and After
Error Categories
CodeCall categorizes all errors for safe exposure:Security Checklist
Before deploying CodeCall to production:1
Choose VM Preset
Use
secure for production, locked_down for sensitive data.2
Configure Tool Allowlists
Limit which tools are accessible via CodeCall.
3
Verify Stack Trace Sanitization
Output sanitization is enabled by default. Verify that error responses don’t leak file paths or internal details in your staging environment.
4
Test Security Boundaries
Run the attack vector tests from ast-guard’s security audit.
Threat Model
What CodeCall Protects Against
Code Injection
AST validation blocks eval, Function, and dynamic code execution
Sandbox Escape
Isolated vm context with no access to Node.js APIs or globals
Data Exfiltration
Tool access control and iteration limits restrict data movement patterns
Prototype Pollution
Blocked at AST level and isolated at runtime
Resource Exhaustion
Timeouts, iteration limits, and tool call caps
I/O Flood Attacks
Console output size and call count limits prevent logging abuse
Information Leakage
Stack traces and file paths sanitized from outputs
Recursive Execution
Self-reference guard blocks codecall:* tool calls
What CodeCall Does NOT Protect Against
Related Documentation
AST Guard
Deep dive into AST validation rules, presets, and custom rule creation (separate repository)
Enclave
Runtime sandbox configuration, sidecar storage, and advanced options (separate repository)
Security Audit
Full list of 100+ blocked attack vectors including Layer 0 Pre-Scanner
Configuration
Complete configuration reference for security settings
AgentScript Guide
What’s allowed and blocked in the scripting language
Production & Scaling
Security checklist and best practices for production