Skip to content

AttackHaltError

Defined in: _worktrees/docs-release/gaunt-sloth/packages/core/src/core/shell/approvalStop.ts:356

§4.2 — an attack outcome: the command’s own structure evidenced compromise (§4.1.1 — credential targeting, privilege escalation, persistence, deception, obfuscation). Ends the agent loop; the model is told nothing and offered nothing.

This is what reaches a surface that cannot ask. An interactive surface is offered [[TUI-C68]] §6.1’s red banner first — GthAgentRunner.setAttackHaltCallback, where typing run anyway runs this one command and everything else stops the run — and this error is thrown when no banner is wired, or when the banner is answered with anything but that phrase. A non-interactive session wires nothing and so gets this message directly (§6.2).

The recovery this message names is deliberately the allow-list, not bypass. §4.2 makes approvals.allow the supported way to run such a command unattended (it is consulted before the rater, so it never reaches a halt at all); bypass also works and is far blunter — it turns off the rater, the escalation and the halt together, for every command, for the whole run. It is a last resort, not the answer, and the wording says so in that order.

new AttackHaltError(command, reason, subject?): AttackHaltError

Defined in: _worktrees/docs-release/gaunt-sloth/packages/core/src/core/shell/approvalStop.ts:360

string

string

ApprovalSubject

AttackHaltError

ApprovalStopError.constructor

optional cause?: unknown

Defined in: websites/gauntsloth-docs-site/node_modules/typescript/lib/lib.es2022.error.d.ts:24

ApprovalStopError.cause


readonly command: string

Defined in: _worktrees/docs-release/gaunt-sloth/packages/core/src/core/shell/approvalStop.ts:307

What ended the run, exactly as the agent proposed it: the command for a shell subject, and the registered tool name for a gated tool or MCP call. The field name predates the gate widening past the shell; subjectParts is what decides the word the MESSAGE calls it.

ApprovalStopError.command


message: string

Defined in: websites/gauntsloth-docs-site/node_modules/typescript/lib/lib.es5.d.ts:1075

ApprovalStopError.message


name: string

Defined in: websites/gauntsloth-docs-site/node_modules/typescript/lib/lib.es5.d.ts:1074

ApprovalStopError.name


readonly parts: readonly ApprovalStopPart[]

Defined in: _worktrees/docs-release/gaunt-sloth/packages/core/src/core/shell/approvalStop.ts:310

The message’s pieces, tagged with who wrote each — see ApprovalStopPart.

ApprovalStopError.parts


readonly reason: string

Defined in: _worktrees/docs-release/gaunt-sloth/packages/core/src/core/shell/approvalStop.ts:358

The rater’s explanation of what the command’s structure showed.


optional stack?: string

Defined in: websites/gauntsloth-docs-site/node_modules/typescript/lib/lib.es5.d.ts:1076

ApprovalStopError.stack


static stackTraceLimit: number

Defined in: _worktrees/docs-release/gaunt-sloth/node_modules/.pnpm/@types+node@26.4.0/node_modules/@types/node/globals.d.ts:67

The Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)).

The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed.

If set to a non-number value, or set to a negative number, stack traces will not capture any frames.

ApprovalStopError.stackTraceLimit

static captureStackTrace(targetObject, constructorOpt?): void

Defined in: _worktrees/docs-release/gaunt-sloth/node_modules/.pnpm/@types+node@26.4.0/node_modules/@types/node/globals.d.ts:51

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack; // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
b();
}
function b() {
c();
}
function c() {
// Create an error without stack trace to avoid calculating the stack trace twice.
const { stackTraceLimit } = Error;
Error.stackTraceLimit = 0;
const error = new Error();
Error.stackTraceLimit = stackTraceLimit;
// Capture the stack trace above function b
Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
throw error;
}
a();

object

Function

void

ApprovalStopError.captureStackTrace


static prepareStackTrace(err, stackTraces): any

Defined in: _worktrees/docs-release/gaunt-sloth/node_modules/.pnpm/@types+node@26.4.0/node_modules/@types/node/globals.d.ts:55

Error

CallSite[]

any

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

ApprovalStopError.prepareStackTrace