Repository navigation
Conversation
Idea credit: NVIDIA's Open Agent Safety Platform — monitoring on the node's only path to the model, out of the agent's reach. The agent's audit log lives in the process it audits, so a compromised agent can drop entries. With PROXY_WIRE_RECORD set, the forward proxy appends one line per model response (OpenAI chat/Responses and Anthropic, JSON or SSE): host, path, status, model, request hash, size, and the tool calls the model returned as names + argument hashes — never text. Lines are hash-chained, so an edit, deletion or reordering breaks the chain (python -m secrets_proxy.wire_record verify). Tamper-evident, not tamper-proof: keep the file writable only by the proxy and anchor the head hash off the box. Recording never breaks a response.
Dev and prod can share the forward proxy; the caller label (the proxy username) is captured before the credential is stripped and written on each wire line, so a check runs against one instance's traces.
… after stripping it Every injection audit line said caller=-. Read the caller once, before the strip, and use it for both the audit line and the wire record.
Owner
Author
|
Added a fix found while reading this code: the injection audit line has always logged |
This was referenced Sep 30, 2026
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Idea credit: NVIDIA's Open Agent Safety Platform: monitoring "on the node's only path to the model", out of the agent's reach. Assessed in praxagent/prax#246.
Why. An agent's audit log and traces live in the process they audit, so a compromised agent can drop its own entries. This proxy is on the model path and outside that process.
What (
PROXY_WIRE_RECORD, default off;secrets_proxy/wire_record.py). The forward proxy appends one line per model response. It parses OpenAI chat, the OpenAI Responses API and Anthropic, as JSON or SSE, and reassembles streamed tool-call arguments. Each line holds caller, host, path, status, model, request hash, size, and the tool calls the model returned as names + argument hashes, never text.python -m secrets_proxy.wire_record verify FILE)../wirewritable only by the proxy and anchor the head hash off the box. The README says so.caller(the proxy username) separates instances sharing the proxy, e.g. dev and prod.stream_large_bodies(1 MB) are recorded by size only; documented.wire/is gitignored (runtime data).Prax's side (
scripts/check_wire_record.py, compare the record with Prax's traces) follows in a prax PR. Its chain check was cross-verified against records written by this code.Tests:
tests/test_wire_record.py(11): parsers, no-text guarantee, chaining across restarts, three kinds of tampering, host filtering, the mitmproxy hook. 74 pass; ruff clean.