Part of #16946. Deliberately deferred by the owner (2026-09-18): the confused-deputy fix (#16950) ships first, with this hardening following it.
The gap
Messages on the internal agent bus are not authenticated. The Redis channel in protocols/agent_communication.py rpushes and blpops raw JSON, deserialised by StandardMessage.from_json with no signature check. Any process that can write to that Redis can publish a message whose sender is any registered agent and whose originator is any registered principal — and a receiver's check that those identities are registered passes, because they are.
The identity model's registration gate stops unregistered names. It does not stop impersonation of registered ones. Until this lands, the trust boundary of the agent bus is Redis write access, and that is stated in #16946's design rather than implied away.
Proposed approach
A symmetric key issued at the registration gate, one per registered agent. Each message carries an HMAC over its header and payload; the receiving side verifies it against the key the registry issued for the claimed sender. No PKI, and rotation is re-registration. That is the smallest change that closes forgery by a process holding only bus access.
Acceptance criteria
Part of #16946. Deliberately deferred by the owner (2026-09-18): the confused-deputy fix (#16950) ships first, with this hardening following it.
The gap
Messages on the internal agent bus are not authenticated. The Redis channel in
protocols/agent_communication.pyrpushes andblpops raw JSON, deserialised byStandardMessage.from_jsonwith no signature check. Any process that can write to that Redis can publish a message whosesenderis any registered agent and whoseoriginatoris any registered principal — and a receiver's check that those identities are registered passes, because they are.The identity model's registration gate stops unregistered names. It does not stop impersonation of registered ones. Until this lands, the trust boundary of the agent bus is Redis write access, and that is stated in #16946's design rather than implied away.
Proposed approach
A symmetric key issued at the registration gate, one per registered agent. Each message carries an HMAC over its header and payload; the receiving side verifies it against the key the registry issued for the claimed sender. No PKI, and rotation is re-registration. That is the smallest change that closes forgery by a process holding only bus access.
Acceptance criteria
originatorfield is covered by the MAC, so a relay cannot alter it