Skip to content

adapter-side PII pattern still hard-blocks bare nine-digit numbers (residual of the #3353/#3531 gateway-DoS fix) #3532

Description

@MohammadHaroonAbuomar

PR #3531 fixed the MCP gateway path: the credential_redactor SSN pattern now requires separators, so scan_response('Tracking: 123456789') no longer produces a pii_leak hard-block. Verified during its review: the ADAPTER-side copy of the loose pattern remains: agent-governance-python/agent-os/src/agent_os/integrations/base.py PII_PATTERNS[0] = \b\d{3}[\s.-]?\d{2}[\s.-]?\d{4}\b matches bare nine digits and is used in BLOCKING paths (autogen_adapter DropMessage at lines ~209/260, PolicyViolationError on state updates ~915, bedrock_adapter _PII_RE). A bare tracking/order number in message content still hard-denies on those adapters. Port #3531's separated-forms pattern to base.py (and bedrock's copy), with the same both-direction tests. Also worth harmonizing with the rego reference pattern (policy-engine/policy/lib/patterns.rego:17, detection-only).

Activity

  1. added a commit that references this issue on Sep 14, 2026
    da2ce5d
  2. added a commit that references this issue on Oct 1, 2026
    398c2c9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions