Skip to content

Improve secrets broker, canary token, and validation guidance#1163

Open
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/secrets-broker-canary-gates
Open

Improve secrets broker, canary token, and validation guidance#1163
KooZuKi wants to merge 1 commit into
UnitOneAI:mainfrom
KooZuKi:improve/secrets-broker-canary-gates

Conversation

@KooZuKi
Copy link
Copy Markdown

@KooZuKi KooZuKi commented Jun 5, 2026

Summary

  • Add canary/honey token classification rules so approved monitored tokens are not blindly treated as production leaks or permanently suppressed.
  • Add live validation safety checks for read-only probes, redacted logs, rate limits, and provider side-effect control.
  • Expand agent-specific credential handling with an exposure model for raw secrets, short-lived real secrets, brokered tokens, and capability handles.
  • Add credential broker evidence gates for host/path/method binding, default-deny egress, SSRF protections, audit logs, and fail-closed fallback behavior.

Validation

  • git diff --check
  • Local frontmatter check using the repository workflow required fields
  • Local prompt-injection scan using the repository workflow patterns

Closes #1160

Bounty

Improver contribution. Preferred payment method can be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] secrets-management: add brokered agent credential and canary-token gates

1 participant