Skip to content

[Security] Admit generated agent contracts through a least-privilege policy compiler #11

Description

@pate0304

Outcome

Allow project-specific role synthesis without allowing repository text or model drafts to widen policy, tools, models, paths, outputs, network, or external actions.

Acceptance criteria

  • Repository bytes remain untrusted data and are never copied into persistent developer instructions.
  • Generated drafts use a strict RoleSpec schema and fixed output allowlist.
  • Unknown tools, models, efforts, paths, permissions, and TOML keys fail closed.
  • Read-only is the default; workspace-write requires an implementation work package and explicit human-visible justification.
  • External connectors, credentials, publication, trust, global config, hooks, and MCP installation remain outside automatic generation.
  • Injection and policy-fuzz suites pass.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Done

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions