Four measurements decide the shape, all taken today:
1. --allowedTools is not an enforcement boundary. ListAgents and
ScheduleWakeup ran on microvm missions whose list is Read Edit Write
Bash Agent. The flag governs prompting, not availability, so any
task-permission layer must be enforced by our own gate.
2. The guest already has every tool's output on disk (the tap appends the
whole payload, tool_response included), so taint is computable
guest-locally with no network call and no added latency.
3. The taint store would already be protected — the hook-files rule
refuses reads and writes to /root/toolhooks from both Bash and the
write tools.
4. Provenance is a CONTAINER-tier control. A microVM reaches only the
provider and the forge through a name-matched CONNECT allow-list; a
container reaches any public host. Saying it matters equally on both
would be padding.
Task permission: a per-phase "agent_tools" key (NOT "tools", which
security_scan already owns), defaulted from what phase kinds actually
used, enforced by the gate. Provenance: taint hostnames out of fetched
responses, deny an outbound call WITH A BODY whose target is one of them
— the asymmetry being that reading a host a page mentioned is research
and sending data to it is the attack. String taint is rejected outright
as a false-positive generator, which is this module's cardinal sin.
Both ship in shadow (gate.would_deny) first, because today's corpus is
171 tool calls and 15 curl invocations and cannot validate a rule.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01WZb5A2kfVfjpdwSochkuHz