一键导入
tlamatini-csrf-exempt-audit
Enumerate every @csrf_exempt-decorated view in Tlamatini/agent/views.py and classify whether each one really needs the exemption.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Enumerate every @csrf_exempt-decorated view in Tlamatini/agent/views.py and classify whether each one really needs the exemption.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Run the daily automated Tlamatini chat regression — drive a visible Chrome via Playwright, log into agent_page.html, ask up to 1000 curated safe questions one-by-one (Multi-Turn ON, ACPX/Ask-Execs/Exec-Report/Internet OFF), wait for and qualify each answer (heuristic + LLM judge on failures), then write a dated report + summary. Invoke when the user says "run the daily chat test", "test Tlamatini with the 1000 questions", "daily Tlamatini regression", or schedules this test.
Turn a natural-language objective into a downloadable .flw workflow by driving the FlowCreator engine (full 83-agent catalog), then emit a canvas-loadable .flw.
The authoritative, exhaustive end-to-end runbook for creating a BRAND-NEW Tlamatini workflow agent — every surface, in order, with 530+ numbered steps across 26 phases. Invoke whenever Angela says "create a new agent", "add an agent", "make a <X>er agent", "I want a new canvas agent", or asks to wire any new pool agent across backend + frontend + Multi-Turn + Parametrizer + FlowCreator + FlowHypervisor + watchdog + config dialog + demo prompts + Python tests + Playwright harness tests + docs + packaging. Covers naming, coloring, the inputs/outputs connector contract in agentic_control_panel.html, the Multi-Turn (wrapped chat-agent) tool, Exec Report, the configuration dialog, automated unit tests AND Playwright tests in Claude's harness. Pairs with tlamatini-agent-naming (casing) and the @-imported create_new_agent.md / create_new_mcp.md.
Build and edit in Roblox Studio via the Roblox Studio MCP the RIGHT way - preflight the Studio connection, do the whole build in a few big execute_luau scripts (not dozens of tiny calls), make REALISTIC terrain with the Terrain VOXEL api driven by Perlin noise (NEVER stacked Parts or concentric layers - those give ugly blocky stepped pyramids), poll generative jobs, check the console, and fail honestly. Invoke for ANY "in Roblox / Roblox Studio" request - terrain, mountains, parts, scripts, models, materials, assets.
The authoritative 8-step contract for scaffolding a NEW Tlamatini workflow agent end-to-end (backend script + config.yaml, connection-update view + URL, migration seeding the Agent row, CSS gradient, four JS files, agentic_skill.md, README.md, lint). READ THIS BEFORE adding or renaming any of the 83 visual agents, before touching `agent/agents/<name>/`, before writing a `00NN_add_<name>.py` migration, before adding a `.canvas-item.<x>-agent` rule, or before extending the `acp-*.js` classMap / connectors. Companion to the `tlamatini-new-acp-agent` skill (which drives the procedure) and to `tlamatini-agent-naming` (the naming-convention guard).
Turn a one-sentence objective into a downloadable .flw workflow that wires the right Tlamatini visual agents and connections.
| name | tlamatini-csrf-exempt-audit |
| description | Enumerate every @csrf_exempt-decorated view in Tlamatini/agent/views.py and classify whether each one really needs the exemption. |
| metadata | {"openclaw":{"emoji":"🛡"},"tlamatini":{"runtime":"in-process","requires_tools":["chat_agent_executer"],"requires_mcps":["Files-Search"],"budget":{"max_iterations":4,"max_seconds":60,"max_tokens":12000},"permissions":{"filesystem":{"read":["Tlamatini/agent/views.py","Tlamatini/agent/urls.py"],"write":[]},"shell":[],"network":"deny","db":"deny"},"inputs":[],"outputs":[{"name":"total","type":"integer","required":true},{"name":"classifications","type":"array","required":true},{"name":"recommendations","type":"array","required":true}],"triggers":{"keywords":["csrf","csrf_exempt","csrf audit"]}}} |
The TlamatiniVsOpenClaw report counted 60+ @csrf_exempt decorators in
Tlamatini/agent/views.py. Most are necessary for WebSocket-adjacent
JSON endpoints, but the wholesale exemption is a security smell.
Tlamatini/agent/views.py for @csrf_exempt.unsafe-without-csrf: state-changing POST that should NOT be exempt.safe-because-websocket: feeds a WebSocket session-restore path.safe-because-internal-tool: only callable by Tlamatini's own JS;
a CSRF token would be appropriate.unknown: needs human review.safe-because-websocket row, propose the smallest fix
(token tag, middleware exception, view rewrite).Return { total, classifications: [{view_name, kind}], recommendations: [...] }.