Skip to content

[Security][P2] Runtime composition policy engine (MVP) #19

@EXboys

Description

@EXboys

Goal

在多 Skill 动态编排时执行组合策略校验,阻断“低信任 Skill 处理高敏数据”与“隐式权限升级”。

Task checklist

  • 定义组合图输入(节点=skill/tool,边=数据流)
  • 实现最小策略规则(trust tier × data_class × action)
  • 在执行前进行 preflight policy check
  • 对拒绝决策给出可解释原因
  • 审计记录组合图摘要与决策结果

Acceptance criteria

  • 典型违规链路(unknown skill + secret data)被阻断
  • 合规链路可正常执行
  • 审计可重建关键决策路径

Dependencies

  • Issue 6

Estimate

4–5 天

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentAgent related changesruntime-policyRuntime policy engine and checkssecuritySecurity related work

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions