feat(plugins): add modelOverride/providerOverride to before_agent_start hook

Enable plugins to override the model and provider for agent runs by
returning modelOverride/providerOverride from the before_agent_start
hook. The hook is now invoked early in run.ts (before resolveModel)
so overrides take effect. The result is passed to attempt.ts via
earlyHookResult to prevent double-firing.

This enables security-critical use cases like routing PII-containing
prompts to local models instead of cloud providers.
This commit is contained in:
Nate Fikru
2026-02-15 12:05:29 -05:00
committed by Peter Steinberger
parent 15dd2cda20
commit b90eb51520
5 changed files with 73 additions and 25 deletions

View File

@@ -1,7 +1,9 @@
import fs from "node:fs/promises";
import type { ThinkLevel } from "../../auto-reply/thinking.js";
import type { PluginHookBeforeAgentStartResult } from "../../plugins/types.js";
import type { RunEmbeddedPiAgentParams } from "./run/params.js";
import type { EmbeddedPiAgentMeta, EmbeddedPiRunResult } from "./types.js";
import { getGlobalHookRunner } from "../../plugins/hook-runner-global.js";
import { enqueueCommandInLane } from "../../process/command-queue.js";
import { isMarkdownCapableMessageChannel } from "../../utils/message-channel.js";
import { resolveOpenClawAgentDir } from "../agent-paths.js";
@@ -198,13 +200,43 @@ export async function runEmbeddedPiAgent(
}
const prevCwd = process.cwd();
const provider = (params.provider ?? DEFAULT_PROVIDER).trim() || DEFAULT_PROVIDER;
const modelId = (params.model ?? DEFAULT_MODEL).trim() || DEFAULT_MODEL;
let provider = (params.provider ?? DEFAULT_PROVIDER).trim() || DEFAULT_PROVIDER;
let modelId = (params.model ?? DEFAULT_MODEL).trim() || DEFAULT_MODEL;
const agentDir = params.agentDir ?? resolveOpenClawAgentDir();
const fallbackConfigured =
(params.config?.agents?.defaults?.model?.fallbacks?.length ?? 0) > 0;
await ensureOpenClawModelsJson(params.config, agentDir);
// Run before_agent_start hooks early so plugins can override the model
// before it gets resolved. The hook result is passed downstream to
// attempt.ts to avoid double-firing.
let earlyHookResult: PluginHookBeforeAgentStartResult | undefined;
const hookRunner = getGlobalHookRunner();
if (hookRunner?.hasHooks("before_agent_start")) {
try {
earlyHookResult = await hookRunner.runBeforeAgentStart(
{ prompt: params.prompt },
{
agentId: params.agentId,
sessionKey: params.sessionKey,
sessionId: params.sessionId,
workspaceDir: params.workspaceDir,
messageProvider: params.messageProvider ?? undefined,
},
);
if (earlyHookResult?.providerOverride) {
provider = earlyHookResult.providerOverride;
log.info(`[hooks] provider overridden to ${provider}`);
}
if (earlyHookResult?.modelOverride) {
modelId = earlyHookResult.modelOverride;
log.info(`[hooks] model overridden to ${modelId}`);
}
} catch (hookErr) {
log.warn(`before_agent_start hook (early) failed: ${String(hookErr)}`);
}
}
const { model, error, authStorage, modelRegistry } = resolveModel(
provider,
modelId,
@@ -479,6 +511,7 @@ export async function runEmbeddedPiAgent(
streamParams: params.streamParams,
ownerNumbers: params.ownerNumbers,
enforceFinalTag: params.enforceFinalTag,
earlyHookResult,
});
const {