Skip to content

[REVIEW] agent-security: bind approvals to artifacts and tool provenance#1599

Open
xianzuyang9-blip wants to merge 1 commit into
UnitOneAI:mainfrom
xianzuyang9-blip:codex/agent-security-approval-provenance
Open

[REVIEW] agent-security: bind approvals to artifacts and tool provenance#1599
xianzuyang9-blip wants to merge 1 commit into
UnitOneAI:mainfrom
xianzuyang9-blip:codex/agent-security-approval-provenance

Conversation

@xianzuyang9-blip
Copy link
Copy Markdown

Summary

Addresses #1595 for the agent-security skill by adding explicit review gates for:

  • approval decisions bound to canonical executable artifacts instead of model-written summaries
  • MCP/plugin/tool-server provenance, version pinning, manifest review, and per-server secret scoping
  • privacy-preserving audit alternatives such as prompt hashes, redacted parameters, policy traces, and correlation IDs

Verification

  • git diff --check
  • Confirmed the update is scoped to skills/ai-security/agent-security/SKILL.md

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant