Preflight
Issue origin
Observed or reproduced in a real environment
LoopX version or commit
main @ 07eb7a1
Host or runtime surface
Not host-specific
LoopX area
Capability or extension (providers, adapters, skills)
Problem
loopx/capabilities/content_ops/cli.py::_load_json_object reads stdin with sys.stdin.read() before parsing JSON, with no maximum size. The queue-status and item-transition commands explicitly accept - for JSON input, so a piped oversized payload is fully buffered in memory before validation. A very large or accidentally unbounded input can exhaust memory in this CLI process. This issue is limited to the stdin path; it does not claim that every JSON file reader should share one universal limit.
Minimal reproduction
On main at 07eb7a1288e8a33995493f9d50475f2664fcbf2e, run a content-ops command that accepts --item-json - and pipe an input stream larger than the desired CLI input bound. _load_json_object calls sys.stdin.read() without a byte limit, so it buffers the entire stream before json.loads runs.
Expected behavior
The stdin reader should enforce a documented maximum byte size and return a clear validation error when the limit is exceeded, before allocating the complete input in memory.
Actual behavior
The - branch invokes json.loads(sys.stdin.read()) directly. It has no bounded read or pre-parse size check.
Sanitized diagnostics
Confirmed by source inspection on synthetic input; no private files, credentials, or runtime state involved.
Additional context
No response
Preflight
Issue origin
Observed or reproduced in a real environment
LoopX version or commit
main @ 07eb7a1
Host or runtime surface
Not host-specific
LoopX area
Capability or extension (providers, adapters, skills)
Problem
loopx/capabilities/content_ops/cli.py::_load_json_objectreads stdin withsys.stdin.read()before parsing JSON, with no maximum size. Thequeue-statusanditem-transitioncommands explicitly accept-for JSON input, so a piped oversized payload is fully buffered in memory before validation. A very large or accidentally unbounded input can exhaust memory in this CLI process. This issue is limited to the stdin path; it does not claim that every JSON file reader should share one universal limit.Minimal reproduction
On main at
07eb7a1288e8a33995493f9d50475f2664fcbf2e, run a content-ops command that accepts--item-json -and pipe an input stream larger than the desired CLI input bound._load_json_objectcallssys.stdin.read()without a byte limit, so it buffers the entire stream beforejson.loadsruns.Expected behavior
The stdin reader should enforce a documented maximum byte size and return a clear validation error when the limit is exceeded, before allocating the complete input in memory.
Actual behavior
The
-branch invokesjson.loads(sys.stdin.read())directly. It has no bounded read or pre-parse size check.Sanitized diagnostics
Additional context
No response