Summary
Mesh messages decrypted by the plugin are processed without policy evaluation. A trusted peer could send task requests that should be blocked by policy.
Details
File: cli/src/plugin.ts, lines 156-305 (onMessage handler)
Once E2E-decrypted, task_request messages are delegated directly to the native agent. No check whether:
- The requested action is allowed by policy
- The sender's trust score warrants this level of access
- The request type (tool call, file access, spawn) is permitted from a peer
Proposed Fix
// Before delegateToNativeAgent:
const decision = await agtPolicy.evaluate({
action: "handle_mesh_request",
message_type: msg.message_type,
from_agent: msg.from_agent,
trust_score: trustStore.get(msg.from_agent)?.score
});
if (decision !== "allow") {
console.log(`Blocked mesh request from ${msg.from_agent}: ${decision}`);
return;
}
AGT's inter-agent trust protocol (IATP) provides exactly this pattern.
References
- plugin.ts lines 156-305
- AGT: trust-protocol IATP handshake verification
Summary
Mesh messages decrypted by the plugin are processed without policy evaluation. A trusted peer could send task requests that should be blocked by policy.
Details
File:
cli/src/plugin.ts, lines 156-305 (onMessagehandler)Once E2E-decrypted,
task_requestmessages are delegated directly to the native agent. No check whether:Proposed Fix
AGT's inter-agent trust protocol (IATP) provides exactly this pattern.
References