Summary
Several operations that should be audited via AGT audit chain are not:
| Operation |
File:Line |
Risk |
Model override via /admin/model |
routes.rs:651-673 |
Model switch to expensive/unsafe model unlogged |
| Heartbeat frequency |
plugin.ts:59-62 |
No rate limit on mesh heartbeat spam |
| Foundry agent ID injection |
reconciler.rs:566-573 |
External ID accepted without format validation |
| Learn mode bulk promote |
routes.rs:1789-1821 |
50+ domains auto-promoted to allowlist without review gate |
Proposed Fix
Each operation should call governance.audit.append() and optionally require policy evaluation:
// Model switch
governance.audit.append("admin:model_switch", &format!("to {}", model)).await;
let decision = governance.evaluate_action(&format!("switch_model:{}", model)).await;
// Foundry agent ID validation
if !agent_id.chars().all(|c| c.is_ascii_hexdigit() || c == '-') {
return Err("Invalid agent ID format");
}
// Learn mode promote gate
if learned_domains.len() > 50 {
let decision = governance.evaluate_action("egress:bulk_promote").await;
if decision == RequiresApproval { return pending(); }
}
AGT's hash-chain audit log with Ed25519 signatures would make all these operations tamper-evident.
References
- AGT: AuditChain, PolicyEngine
Summary
Several operations that should be audited via AGT audit chain are not:
/admin/modelProposed Fix
Each operation should call
governance.audit.append()and optionally require policy evaluation:AGT's hash-chain audit log with Ed25519 signatures would make all these operations tamper-evident.
References