Skip to content

security: sub-agent spawn not gated by policy or trust score #8

Description

Summary

spawn.rs allows any agent to create sub-agents without policy evaluation. There is no limit on spawn count, no trust threshold check, and no policy delegation model (parent policies don't flow to children).

Details

File: inference-router/src/spawn.rs, lines 75-231

  • Isolation inheritance is enforced (confidential parent -> confidential child) - good
  • But NO policy evaluation before CRD creation
  • No check: "does this agent's trust score allow spawning?"
  • No limit: "max N sub-agents per parent"
  • No delegation narrowing: child could have broader policy than parent

Proposed Fix

Before CRD creation, evaluate:

let decision = governance.evaluate_action("sandbox:spawn").await;
if decision != Allow { return Err("Spawn denied by policy"); }

// Also enforce limits
let child_count = list_children(parent_name).await?.len();
if child_count >= policy.max_children.unwrap_or(10) {
    return Err("Max sub-agents reached");
}

AGT's delegation narrowing pattern ensures children can never have broader permissions than parents.

References

  • spawn.rs lines 75-231
  • AGT trust-protocol: delegation narrowing

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions