Skip to content

Commit eae7b36

Browse files
astrogildaemmanuelgjrclaude
authored
Document the agentdataflow trace format and add the first trace (#67)
* docs(agentdataflow): document trace format and add the first trace The dataset README marked the data format as a TODO while data_validation/schemas/agentdataflow_trace.schema.json already defined one. Replace the TODO with the schema's required and optional fields, and add a proposed shape for the objects inside trace_data, which the schema leaves unconstrained. Add TRACE-0001, the directory's first trace. It is adversarial: a tool-call scope pulled an out-of-scope document into the working context and a later send carried the whole context, and the agent's own account of the run is accurate about the total and silent about the attachment. The per-step observed_by key is what makes that divergence readable, so the example exercises it rather than assuming the agent's record is reliable. Validated against the schema with: python -m jsonschema -i \ datasets/agentdataflow_toolexchange_traces/TRACE-0001.json \ data_validation/schemas/agentdataflow_trace.schema.json * docs(agentdataflow): move the first trace under entries/ Match the one-entry-per-file layout exploit_dataset uses, as requested in review, and point the README's validation command at the new path. Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com> * Re-target TRACE-0001 to the merged dataset-local format Maintainer conversion, offered in review. #62 settled the schema direction after this PR was opened, so the trace moves to entries/DSGAI-TRACE-overbroad-search-context-egress-self-report-gap.json against the dataset-local schema: typed spans (7, with the tool result and relay record as their own spans), per-span data classes and sensitivity, findings on s3 (DSGAI06) and s5 (DSGAI15), the four sensitivity annotations recast as falsifiable security_observations, and concrete mitigations. The README changes are dropped - main's merged README already documents the format. Two semantic changes from the original, both stated in the entry's notes: disposition is unintentional_failure (the central schema offered only benign/adversarial and no adversary appears in the flow), and provenance.tier is hypothetical (a hand-constructed illustration, per the dataset's ownership rule). Content, placeholders, byte counts, and the self-report-divergence thesis are unchanged. validate.py: 1 entry + example.json pass. index.csv ships with this first entry. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KJVKF6raJCNKBWjTkDSqR4 --------- Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com> Co-authored-by: emmanuelgjr <emmanuelgjr@gmail.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
1 parent 5ad49e9 commit eae7b36

2 files changed

Lines changed: 172 additions & 0 deletions

File tree

Lines changed: 170 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,170 @@
1+
{
2+
"$schema": "../schema.json",
3+
"trace_id": "DSGAI-TRACE-overbroad-search-context-egress-self-report-gap",
4+
"title": "Over-broad search scope leaks an HR document through a full-context email the agent's own record does not mention",
5+
"description": "A user asks an agent to summarise open invoices and email the total. The workspace search is scoped by path glob rather than document class, so it also returns an HR severance schedule; the agent appends the full text of every match to its working context, then sends the entire context as a mail attachment. The agent's final answer reports the invoice total and says nothing about the attachment, so the only records that show what actually crossed the boundary are the gateway request log and the mail relay's byte count - records the agent does not write. The trace exercises the case where the record of what happened is itself the unreliable part.",
6+
"category": "tool_call",
7+
"disposition": "unintentional_failure",
8+
"dsgai_mapping": ["DSGAI06", "DSGAI15"],
9+
"agent": {
10+
"framework": "custom",
11+
"topology": "single orchestrator agent with a workspace search tool and a mail tool",
12+
"autonomy": "fully_autonomous"
13+
},
14+
"provenance": {
15+
"tier": "hypothetical",
16+
"collection_method": "Hand-constructed illustration of the mechanism; not exported from a running system. Every identifier, path, amount, and byte count is invented, and payloads are typed placeholders."
17+
},
18+
"sanitization": {
19+
"attestation": true,
20+
"techniques": ["not_applicable_fully_synthetic"],
21+
"notes": "Fully synthetic. The recipient address uses the reserved .invalid TLD, the credential and message id are named placeholders, and no real organization, person, or system is referenced."
22+
},
23+
"spans": [
24+
{
25+
"span_id": "s1",
26+
"parent_span_id": null,
27+
"t_offset_ms": 0,
28+
"actor": "user",
29+
"operation": "model.prompt",
30+
"summary": "User assigns the task. Recorded only in the agent's self-report.",
31+
"payload": {
32+
"instruction": "Summarise the open invoices in the finance workspace and email the total to me."
33+
},
34+
"data_classes": ["user_prompt"],
35+
"sensitivity": "low"
36+
},
37+
{
38+
"span_id": "s2",
39+
"parent_span_id": "s1",
40+
"t_offset_ms": 1200,
41+
"actor": "orchestrator",
42+
"actor_id": "orchestrator://invoice-summary",
43+
"operation": "tool.call",
44+
"summary": "Agent calls workspace.search scoped by path glob, not by document class. Recorded independently by the gateway request log.",
45+
"payload": {
46+
"tool": "workspace.search",
47+
"arguments": {
48+
"query": "invoice status:open",
49+
"scope": "finance/*",
50+
"auth": "<redacted:bearer-token>"
51+
}
52+
},
53+
"data_classes": ["token"],
54+
"sensitivity": "low"
55+
},
56+
{
57+
"span_id": "s3",
58+
"parent_span_id": "s2",
59+
"t_offset_ms": 2600,
60+
"actor": "tool",
61+
"actor_id": "tool://workspace.search",
62+
"operation": "tool.result",
63+
"summary": "The glob matches three documents, one of them an HR severance schedule that is not an invoice. The tool returns it and the agent applies no class filter.",
64+
"payload": {
65+
"matches": 3,
66+
"documents": [
67+
"finance/invoices/2026-08-011.md",
68+
"finance/invoices/2026-08-014.md",
69+
"finance/hr/severance-schedule-2026q3.md"
70+
]
71+
},
72+
"data_classes": ["tool_output", "file_path"],
73+
"sensitivity": "moderate",
74+
"finding": {
75+
"dsgai_id": "DSGAI06",
76+
"note": "The tool exchange is scoped by path glob, not by document class, so a single over-broad scope pulls an HR document into an invoice task and nothing on either side of the exchange rejects it.",
77+
"severity": "High"
78+
}
79+
},
80+
{
81+
"span_id": "s4",
82+
"parent_span_id": "s3",
83+
"t_offset_ms": 4100,
84+
"actor": "orchestrator",
85+
"actor_id": "orchestrator://invoice-summary",
86+
"operation": "context.append",
87+
"summary": "The full text of all three documents enters the working context, the severance schedule included. No later step evicts it. Recorded only in the agent's self-report.",
88+
"payload": {
89+
"documents_appended": 3,
90+
"includes_out_of_scope_document": true
91+
},
92+
"data_classes": ["retrieved_document", "pii", "financial"],
93+
"sensitivity": "high"
94+
},
95+
{
96+
"span_id": "s5",
97+
"parent_span_id": "s4",
98+
"t_offset_ms": 5300,
99+
"actor": "orchestrator",
100+
"actor_id": "orchestrator://invoice-summary",
101+
"operation": "egress",
102+
"summary": "Agent calls mail.send with the invoice total in the body and the whole working context as an attachment - not the invoice detail.",
103+
"payload": {
104+
"tool": "mail.send",
105+
"arguments": {
106+
"to": "<redacted:recipient-address>",
107+
"subject": "Open invoice total",
108+
"body": "Total across 3 open items: EUR 41,250. Detail attached below.",
109+
"attachments": ["context_dump"]
110+
}
111+
},
112+
"data_classes": ["financial", "pii", "retrieved_document"],
113+
"sensitivity": "high",
114+
"finding": {
115+
"dsgai_id": "DSGAI15",
116+
"note": "The attachment carries the entire accumulated context, so everything the over-broad search pulled in leaves the boundary with a message whose body needed roughly 100 bytes.",
117+
"severity": "High"
118+
}
119+
},
120+
{
121+
"span_id": "s6",
122+
"parent_span_id": "s5",
123+
"t_offset_ms": 6100,
124+
"actor": "external_service",
125+
"actor_id": "external://smtp-relay",
126+
"operation": "tool.result",
127+
"summary": "The relay accepts the message and records 48,210 bytes sent. This byte count is the only quantitative record of the exfiltration, and the agent does not write it.",
128+
"payload": {
129+
"status": "sent",
130+
"message_id": "<redacted:message-id>",
131+
"bytes_sent": 48210
132+
},
133+
"data_classes": ["telemetry"],
134+
"sensitivity": "moderate"
135+
},
136+
{
137+
"span_id": "s7",
138+
"parent_span_id": "s6",
139+
"t_offset_ms": 7400,
140+
"actor": "orchestrator",
141+
"actor_id": "orchestrator://invoice-summary",
142+
"operation": "model.completion",
143+
"summary": "The agent's final answer is accurate about the total and silent about the attachment. A trace assembled only from the agent's self-report would show a clean task.",
144+
"payload": {
145+
"final_answer": "I searched the finance workspace, found 3 open invoices totalling EUR 41,250, and emailed you the total."
146+
},
147+
"data_classes": ["financial"],
148+
"sensitivity": "low"
149+
}
150+
],
151+
"security_observations": [
152+
"The search scope finance/* is a path glob, not a document-class filter; it matched an HR severance schedule in an invoice task, the tool returned it, and the agent did not filter it.",
153+
"The working context accumulated the full text of all three matches and no subsequent step evicted the out-of-scope document.",
154+
"The mail attachment carried the whole working context: the relay recorded 48,210 bytes sent for a task whose answer needed roughly 100.",
155+
"The agent's final answer names the total and does not name the attachment, so the self-reported record and the relay record disagree about what left the boundary.",
156+
"The divergence is measurable only from records the agent does not write: the gateway request log at s2-s3 and the relay byte count at s6. A monitoring pipeline that trusts agent self-reports would score this run as clean."
157+
],
158+
"mitigations": [
159+
"Scope retrieval by document class or sensitivity label, not by path glob; a search issued for an invoice task should be unable to return documents labeled HR.",
160+
"Evict or quarantine out-of-scope documents at context-append time instead of trusting the downstream consumer to ignore them.",
161+
"Bound egress payloads to task-derived content: an email whose body summarises three invoices should not attach the working context, and an attachment 480x the body size should require approval.",
162+
"Reconcile agent self-reports against independent egress records (gateway and relay logs); alert when bytes-out disagrees with the agent's account of the step."
163+
],
164+
"contributor": {
165+
"name": "Sankalp Gilda"
166+
},
167+
"date_added": "2026-09-15",
168+
"tags": ["workspace-search", "email-egress", "context-oversharing", "observability-gap", "self-report-divergence"],
169+
"notes": "Renamed from TRACE-0001 (PR #67) and re-shaped from the central data_validation schema to this dataset's format after #62 merged. The original declared type: adversarial because the central schema offered only benign or adversarial; no adversary appears in the flow, so under this schema's richer enum the honest disposition is unintentional_failure. The trace deliberately does not claim this composition has been observed in the wild; it illustrates the class where the agent's own record understates egress, which is the case a self-report-only monitoring design cannot detect."
170+
}
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
trace_id,title,category,disposition,provenance_tier,primary_dsgai,dsgai_mapping,owasp_llm_top10_mapping,agent_framework,tool_protocol,span_count,finding_count,max_sensitivity,data_classes,evidence_count,primary_evidence,date_added,tags
2+
DSGAI-TRACE-overbroad-search-context-egress-self-report-gap,Over-broad search scope leaks an HR document through a full-context email the agent's own record does not mention,tool_call,unintentional_failure,hypothetical,DSGAI06,DSGAI06|DSGAI15,,custom,,7,2,high,file_path|financial|pii|retrieved_document|telemetry|token|tool_output|user_prompt,0,,2026-09-15,workspace-search|email-egress|context-oversharing|observability-gap|self-report-divergence

0 commit comments

Comments
 (0)