You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
OCA-owned environment agents (build base, general base, explore, librarian, mechanic) should declare tool permissions explicitly in agent frontmatter. ADV agents are out of scope for this issue — see companion ADV issue.
Why
Current model: agents get all tools by default and opt-out via frontmatter. New tools are automatically exposed to all agents — including tools that shouldn't be available (e.g., explore with bash access).
Scope
Under the cross-repo boundary, OCA owns the base agent files for environment agents. Advance overlays its ADV-specific blocks but doesn't own the base permission declarations.
Summary
OCA-owned environment agents (
buildbase,generalbase,explore,librarian,mechanic) should declare tool permissions explicitly in agent frontmatter. ADV agents are out of scope for this issue — see companion ADV issue.Why
Current model: agents get all tools by default and opt-out via frontmatter. New tools are automatically exposed to all agents — including tools that shouldn't be available (e.g.,
explorewith bash access).Scope
Under the cross-repo boundary, OCA owns the base agent files for environment agents. Advance overlays its ADV-specific blocks but doesn't own the base permission declarations.
build(base)general(base)explorelibrarianmechanicadv,plan,adv-engineer,adv-tron,adv-atc,adv-researcherAcceptance Criteria
oca doctor --scope agentsvalidates permission declarations for OCA-owned agentsCompanion ADV issue
ADV agents need the same treatment — tracked separately.
Proposal
docs/proposals/2026-05-03-agent-permission-first-config.mdWSJF Estimate
Value: 5 | TC: 3 | RROE: 5 | Effort: 3 | WSJF: 2.7