Skip to content

security: inference requests bypass policy evaluation entirely (CRITICAL) #7

Description

Summary

The primary inference path (/v1/chat/completions, /v1/completions) does not call governance policy evaluation before forwarding to the model. Additionally, the /agt/evaluate endpoint is a stub that returns Allow for everything.

Details

Gap 1 — routes.rs:989 (agt_evaluate): The policy evaluation endpoint accepts any action and returns Allow. No actual policy file is loaded or evaluated.

Gap 2 — routes.rs:332-503 (chat_completions): Requests flow through Content Safety → token budget → proxy. There is no governance.evaluate_action() call. A policy that says "block reasoning_model requests in training mode" or "require approval for 100k+ token generations" would never fire.

Impact

This is the most critical gap — the entire inference path has zero policy enforcement. All 708 lines of governance.rs exist but are never invoked on the primary code path.

Proposed Fix (once AGT Rust SDK exists)

After Content Safety checks and before proxying, add:

let decision = governance.evaluate_action(&format!(
    "inference:{}:{}", model, estimated_tokens
)).await;
match decision {
    PolicyDecision::Deny(reason) => return forbidden(reason),
    PolicyDecision::RequiresApproval(_) => return pending_approval(),
    _ => {} // proceed
}

Also, load actual YAML policy from the ConfigMap mount at startup (controller already creates the mount).

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions