Skip to content

Track cross-language skill-aware audit trail hardening parity (TypeScript, .NET, Go, Rust) #2986

Description

Summary

PR #2572 added skill-aware audit trail hardening to the Python agent-os framework integration adapters. This issue tracks porting the equivalent primitives to the other language SDKs where applicable, so governance behavior stays consistent across the ecosystem.

What was added in Python (PR #2572)

  • Trusted skill metadata source (TrustedSkillMetadataSource) so skill name and origin come from framework-owned values, not spoofable request payloads
  • provenance_source_trust provenance marker on audit events
  • UTC-normalized audit timestamps
  • Deterministic, order-stable context hashing with a fail-safe path
  • Spoof-resistance tests across the ADK, CrewAI, Semantic Kernel, OpenAI Agents SDK, AutoGen, and LangChain adapters

Gap in other SDKs

A scan of the other SDKs shows they have framework discovery and detection (recognizing langchain, crewai, autogen, etc.) but none implement the skill-audit primitives above (no trusted_skill / TrustedSkillMetadata, no provenance_source_trust, no emit_skill_audit):

SDK Path Status
TypeScript agent-governance-typescript/ Framework discovery only, no skill-audit primitives
.NET agent-governance-dotnet/ Has Audit and Integration namespaces, no skill-audit primitives
Go agent-governance-golang/ Discovery and audit-chain example only
Rust agent-governance-rust/ Framework integration support only

Proposed work

For each SDK, evaluate whether equivalent framework adapters exist and, where they do, port:

  • trusted skill metadata source extraction (framework-owned, not request-derived)
  • provenance trust marker on audit events
  • UTC-normalized audit timestamps
  • deterministic context hashing
  • spoof-resistance tests

Where a given framework adapter does not exist in a language SDK, no work is required for that adapter and it should be noted as not applicable.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

acceptedenhancementNew feature or requesthelp wantedExtra attention is neededintegrationIntegration adapters for external frameworks

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions