Conversation
Decide-only: Gate.DecideOnly and POST /v1/decide/{tool} rule on a call and
record it without forwarding or holding it. The artifact's outcome says the
gate did not act, and only toolcall.requested and toolcall.decided are
published. For callers that execute tools themselves (a benchmark harness)
and for measuring a policy in shadow before it enforces. Operator-only: an
agent that can ask what would pass can search the policy for values that
slip through.
Tool tags: tool_tags labels tools with classes, and a rule can name a tag
instead of a tool, so one rule governs every tool carrying it. New rule kind
"tool" fires on the action itself (e.g. every destructive tool escalates);
it takes no arg and needs a tool or a tag. Validation refuses tags on tools
missing from tool_scopes, rules on tags no tool carries, rules setting both
tool and tag, and unscoped tool rules.
Existing behaviour is unchanged; all existing tests pass. New tests: the
twelve calls through /v1/decide (same decisions, nothing forwarded, no hold,
chain verifies), the agent refused at /v1/decide, tag scoping, tag
validation, and a tool rule by name.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ptdu2pZMVdE5x6XkwcUDjj
CVE-2026-84445 (HIGH, denial of service via malformed RPC requests) was published for grpc v1.83.1 after main's last security scan, so Trivy now fails for every service that links it. v1.83.2 has the fix. It is an indirect dependency in all fourteen modules that require it; bumping it raises golang.org/x/net to v0.58.0 and, in five modules, golang.org/x/text to v0.41.0 and golang.org/x/sys to v0.47.0, the minimums grpc v1.83.2 requires. Every module builds, vets and passes its tests. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ptdu2pZMVdE5x6XkwcUDjj
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two additions to
aex-toolgatethat keep its approach: declarative policy, deterministic, fail closed, one record per call. Existing behaviour is unchanged and all existing tests pass.Decide-only:
POST /v1/decide/{tool}Gate.DecideOnlyandPOST /v1/decide/{tool}rule on a call and record it, but forward nothing and hold nothing.decided only: not executed by the gate, so the record never reads as an enforced refusal or execution.toolcall.requestedandtoolcall.decidedare published.decision,rule,scope,approval,message,outcome,hash,call_id, plus the usualX-Toolgate-*headers.Use cases: callers that run tools themselves, such as the VetoBench harness (today it points
UPSTREAM_URLat a no-op stub), and measuring a policy in shadow before it enforces.Tool tags
tool_tagslabels tools with classes, and a rule can name ataginstead of atool, so one rule governs every tool carrying the tag.New rule kind
toolfires on the action itself, whatever the arguments, e.g.{"tag": "destructive", "kind": "tool", "effect": "escalate"}. It takes noargand must be scoped by a tool or a tag.Argument rules also work by tag, e.g. a ceiling on every
moneytool. They keep the fail-closed rule for absent arguments.Validation refuses:
tool_scopes;toolandtag;toolrule with anarg, or with neither a tool nor a tag.Each would otherwise leave a tool silently ungoverned or make a rule fire everywhere.
Motivation: VetoBench's Agent-SafetyBench run spans 1,627 tools. Per-tool rules don't scale, but classes ("destructive", "money", "external send") do.
Tests
decide_test.go: the twelve calls through/v1/decidereach the same decisions as/v1/tools, nothing is forwarded, the escalated call leaves no hold, and the chain verifies with 12 records. Without the operator token: 401 and no record.tags_test.go: tag scoping (a tool rule on a tag, a ceiling on a tag, the absent-argument case), each validation error, and a tool rule by name.A question, not changed here
The
Rulecomment says an emptytool"applies it to every tool that carries the argument", butevaluatefails closed when the argument is absent. So a rule without a tool denies every tool that lacks the argument: anamountceiling with no tool denieslist_invoices. Safe, but it makes tool-less rules unusable. Should the code or the comment change? Tags cover the use case either way.🤖 Generated with Claude Code
https://claude.ai/code/session_01Ptdu2pZMVdE5x6XkwcUDjj