PR #3531 fixed the MCP gateway path: the credential_redactor SSN pattern now requires separators, so scan_response('Tracking: 123456789') no longer produces a pii_leak hard-block. Verified during its review: the ADAPTER-side copy of the loose pattern remains: agent-governance-python/agent-os/src/agent_os/integrations/base.py PII_PATTERNS[0] = \b\d{3}[\s.-]?\d{2}[\s.-]?\d{4}\b matches bare nine digits and is used in BLOCKING paths (autogen_adapter DropMessage at lines ~209/260, PolicyViolationError on state updates ~915, bedrock_adapter _PII_RE). A bare tracking/order number in message content still hard-denies on those adapters. Port #3531's separated-forms pattern to base.py (and bedrock's copy), with the same both-direction tests. Also worth harmonizing with the rego reference pattern (policy-engine/policy/lib/patterns.rego:17, detection-only).
PR #3531 fixed the MCP gateway path: the credential_redactor SSN pattern now requires separators, so scan_response('Tracking: 123456789') no longer produces a pii_leak hard-block. Verified during its review: the ADAPTER-side copy of the loose pattern remains: agent-governance-python/agent-os/src/agent_os/integrations/base.py PII_PATTERNS[0] = \b\d{3}[\s.-]?\d{2}[\s.-]?\d{4}\b matches bare nine digits and is used in BLOCKING paths (autogen_adapter DropMessage at lines ~209/260, PolicyViolationError on state updates ~915, bedrock_adapter _PII_RE). A bare tracking/order number in message content still hard-denies on those adapters. Port #3531's separated-forms pattern to base.py (and bedrock's copy), with the same both-direction tests. Also worth harmonizing with the rego reference pattern (policy-engine/policy/lib/patterns.rego:17, detection-only).