Summary
spawn.rs allows any agent to create sub-agents without policy evaluation. There is no limit on spawn count, no trust threshold check, and no policy delegation model (parent policies don't flow to children).
Details
File: inference-router/src/spawn.rs, lines 75-231
- Isolation inheritance is enforced (confidential parent -> confidential child) - good
- But NO policy evaluation before CRD creation
- No check: "does this agent's trust score allow spawning?"
- No limit: "max N sub-agents per parent"
- No delegation narrowing: child could have broader policy than parent
Proposed Fix
Before CRD creation, evaluate:
let decision = governance.evaluate_action("sandbox:spawn").await;
if decision != Allow { return Err("Spawn denied by policy"); }
// Also enforce limits
let child_count = list_children(parent_name).await?.len();
if child_count >= policy.max_children.unwrap_or(10) {
return Err("Max sub-agents reached");
}
AGT's delegation narrowing pattern ensures children can never have broader permissions than parents.
References
- spawn.rs lines 75-231
- AGT trust-protocol: delegation narrowing
Summary
spawn.rsallows any agent to create sub-agents without policy evaluation. There is no limit on spawn count, no trust threshold check, and no policy delegation model (parent policies don't flow to children).Details
File:
inference-router/src/spawn.rs, lines 75-231Proposed Fix
Before CRD creation, evaluate:
AGT's delegation narrowing pattern ensures children can never have broader permissions than parents.
References