Skip to content

[Bug] Guardian-side hook-coverage is unfalsifiable: methods_evaluated allows accept-and-ignore #31

Description

@bar-capsule

Surfaced during Rock's review of PR #21 (item #6 of the review comment). Filing separately since the fix is a spec change beyond that PR's scope.

The gap

ACS spends substantial spec text constraining what the Observed Agent MUST emit, and never constrains what the Guardian MUST evaluate. The ServerHello's methods_evaluated says it plainly:

"Methods listed by the client but absent here are NOT evaluated ... Clients MAY still emit them for audit but MUST treat them as ALLOW-by-default."

So a Guardian can accept every subagent hook a conformant client emits and evaluate none of them, and both parties stay conformant. Every hook-coverage claim in ACS is unfalsifiable from the enforcement side.

Why this matters now

This is the first PR (#21) whose stated security rationale — mandating subagentStart to defend against the confused-deputy attack class — depends on the half that's missing. The client can be forced to emit the hook; nothing forces the Guardian to actually evaluate it against policy. A deployment can advertise ACS-Core conformance, emit every mandatory hook, and still have zero real enforcement, because methods_evaluated lets the Guardian opt out of evaluating what it accepts.

Distinct from #16, which is about the client omitting hooks. This is about the Guardian legitimately declaring it doesn't evaluate hooks it accepts.

Proposed directions (needs design work)

Why deferred from PR #21

Four-line prose relaxations to the ACS-Core disposition/hook sets cannot fix a spec-wide asymmetry between client-emit MUSTs and Guardian-evaluate SHOULDs. The mandate side of the subagent argument holds even without this issue closed; this issue is what makes the mandate checkable.

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:P2Maintainers onlyscope:in-focusFeeds the ninety-day committed outcome. Maintainers onlytype:bugSomething isn't working

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions