Surfaced during Rock's review of PR #21 (item #6 of the review comment). Filing separately since the fix is a spec change beyond that PR's scope.
The gap
ACS spends substantial spec text constraining what the Observed Agent MUST emit, and never constrains what the Guardian MUST evaluate. The ServerHello's methods_evaluated says it plainly:
"Methods listed by the client but absent here are NOT evaluated ... Clients MAY still emit them for audit but MUST treat them as ALLOW-by-default."
So a Guardian can accept every subagent hook a conformant client emits and evaluate none of them, and both parties stay conformant. Every hook-coverage claim in ACS is unfalsifiable from the enforcement side.
Why this matters now
This is the first PR (#21) whose stated security rationale — mandating subagentStart to defend against the confused-deputy attack class — depends on the half that's missing. The client can be forced to emit the hook; nothing forces the Guardian to actually evaluate it against policy. A deployment can advertise ACS-Core conformance, emit every mandatory hook, and still have zero real enforcement, because methods_evaluated lets the Guardian opt out of evaluating what it accepts.
Distinct from #16, which is about the client omitting hooks. This is about the Guardian legitimately declaring it doesn't evaluate hooks it accepts.
Proposed directions (needs design work)
Why deferred from PR #21
Four-line prose relaxations to the ACS-Core disposition/hook sets cannot fix a spec-wide asymmetry between client-emit MUSTs and Guardian-evaluate SHOULDs. The mandate side of the subagent argument holds even without this issue closed; this issue is what makes the mandate checkable.
References
Surfaced during Rock's review of PR #21 (item #6 of the review comment). Filing separately since the fix is a spec change beyond that PR's scope.
The gap
ACS spends substantial spec text constraining what the Observed Agent MUST emit, and never constrains what the Guardian MUST evaluate. The ServerHello's
methods_evaluatedsays it plainly:So a Guardian can accept every subagent hook a conformant client emits and evaluate none of them, and both parties stay conformant. Every hook-coverage claim in ACS is unfalsifiable from the enforcement side.
Why this matters now
This is the first PR (#21) whose stated security rationale — mandating
subagentStartto defend against the confused-deputy attack class — depends on the half that's missing. The client can be forced to emit the hook; nothing forces the Guardian to actually evaluate it against policy. A deployment can advertise ACS-Core conformance, emit every mandatory hook, and still have zero real enforcement, becausemethods_evaluatedlets the Guardian opt out of evaluating what it accepts.Distinct from #16, which is about the client omitting hooks. This is about the Guardian legitimately declaring it doesn't evaluate hooks it accepts.
Proposed directions (needs design work)
methods_evaluatedMUST evaluate it against non-null policy for the session. Conformance tests can drive negative vectors and assert non-ALLOW verdicts fire.agbom/snapshot(client-declared components + observed hook traffic) reconciled againstmethods_evaluated. A Guardian that declares evaluation of a method never seen for a component that should trigger it is flagged.Why deferred from PR #21
Four-line prose relaxations to the ACS-Core disposition/hook sets cannot fix a spec-wide asymmetry between client-emit MUSTs and Guardian-evaluate SHOULDs. The mandate side of the subagent argument holds even without this issue closed; this issue is what makes the mandate checkable.
References
docs/spec/instrument/specification.md—methods_evaluatedsemantics in ServerHello (§4)