Skip to content
Changelog

Restrict what your knowledge readers can fetch

May 15, 20261 min read

URL-fetching knowledge readers now take an allowed_hosts parameter, so a reader pulls only from hosts you trust and rejects everything else. This closes the same SSRF and data-exfiltration surface during knowledge ingestion that any link-following fetcher opens in production.

See cookbook for more reference.

Shipped around the same time