feat(security): enforce read-only actions #322

Closed
opened 2026-02-22 23:41:17 +00:00 by freemo · 1 comment
Owner

Metadata

  • Commit Message: feat(security): enforce read-only actions
  • Branch: feature/m4-security-readonly

Background

Read-only actions are validated to only use read-only skills at execution time. Write-capable tools are blocked in ToolRuntime when the plan/action is read-only, with the tool name included in the error. SkillContext and ChangeSet builder also enforce read-only restrictions.

Acceptance Criteria

  • Validate read-only actions only use read-only skills at execution time.
  • Block write-capable tools in ToolRuntime when plan/action is read-only and include tool name in error.
  • Add read-only enforcement to SkillContext and ChangeSet builder to prevent write artifacts.
  • Add read-only enforcement in CLI commands that would mutate resources (fail fast before execution).
  • Add tests for read-only enforcement on file and git tool calls.

Definition of Done

This issue is complete when:

  • All subtasks below are completed and checked off.
  • A Git commit is created where the first line of the commit message matches
    the Commit Message in Metadata exactly, followed by a blank line, then
    additional lines providing relevant details about the implementation. The
    commit body should be appropriate in size for a commit message and relatively
    complete in describing what was done.
  • The commit is pushed to the remote on the branch matching the Branch in
    Metadata exactly.
  • The commit is submitted as a pull request to master, reviewed, and
    merged before this issue is marked done.

Subtasks

  • Validate read-only actions only use read-only skills at execution time.
  • Block write-capable tools in ToolRuntime when plan/action is read-only and include tool name in error.
  • Add read-only enforcement to SkillContext and ChangeSet builder to prevent write artifacts.
  • Add read-only enforcement in CLI commands that would mutate resources (fail fast before execution).
  • Add tests for read-only enforcement on file and git tool calls.
  • Add docs/reference/read_only_actions.md.
  • Tests (Behave): Add features/security_readonly.feature scenarios.
  • Tests (Robot): Add read-only enforcement integration tests.
  • Tests (ASV): Add benchmarks/security_readonly_bench.py for enforcement overhead baseline.
  • Verify coverage >=97% via nox -s coverage_report. If coverage is <97% then review the current unit test coverage report at build/coverage.xml and use it to write new Behave based unit tests to improve code coverage. Specifically, write Behave style unit tests that are descriptively named and specifically improves coverage on whichever file has the most uncovered lines by writing tests that will target the uncovered lines in the report. Once that is done rerun nox -s coverage_report to verify all tests pass and coverage is above >=97%. Only mark this as complete once coverage is >=97%, if not repeat this task as many times as is needed until coverage reaches >=97%.
  • Run nox (all default sessions, including benchmark), fix any errors if needed ensuring nox passes across entire code base, do not ignore any failure even if it seems unrelated to this commit, fix it.
  • Note: Safety profile enforcement is deferred; see Section 18 POST.safety.

Section: ### Section 11: Security & Safety [WORKSTREAM F - Luis + Brent]
Status: Open

## Metadata - **Commit Message**: `feat(security): enforce read-only actions` - **Branch**: `feature/m4-security-readonly` ## Background Read-only actions are validated to only use read-only skills at execution time. Write-capable tools are blocked in ToolRuntime when the plan/action is read-only, with the tool name included in the error. SkillContext and ChangeSet builder also enforce read-only restrictions. ## Acceptance Criteria - [ ] Validate read-only actions only use read-only skills at execution time. - [ ] Block write-capable tools in ToolRuntime when plan/action is read-only and include tool name in error. - [ ] Add read-only enforcement to SkillContext and ChangeSet builder to prevent write artifacts. - [ ] Add read-only enforcement in CLI commands that would mutate resources (fail fast before execution). - [ ] Add tests for read-only enforcement on file and git tool calls. ## Definition of Done This issue is complete when: - All subtasks below are completed and checked off. - A Git commit is created where the **first line** of the commit message matches the Commit Message in Metadata exactly, followed by a blank line, then additional lines providing relevant details about the implementation. The commit body should be appropriate in size for a commit message and relatively complete in describing what was done. - The commit is pushed to the remote on the branch matching the **Branch** in Metadata exactly. - The commit is submitted as a **pull request** to `master`, reviewed, and **merged** before this issue is marked done. ## Subtasks - [ ] Validate read-only actions only use read-only skills at execution time. - [ ] Block write-capable tools in ToolRuntime when plan/action is read-only and include tool name in error. - [ ] Add read-only enforcement to SkillContext and ChangeSet builder to prevent write artifacts. - [ ] Add read-only enforcement in CLI commands that would mutate resources (fail fast before execution). - [ ] Add tests for read-only enforcement on file and git tool calls. - [ ] Add `docs/reference/read_only_actions.md`. - [ ] Tests (Behave): Add `features/security_readonly.feature` scenarios. - [ ] Tests (Robot): Add read-only enforcement integration tests. - [ ] Tests (ASV): Add `benchmarks/security_readonly_bench.py` for enforcement overhead baseline. - [ ] Verify coverage >=97% via `nox -s coverage_report`. If coverage is <97% then review the current unit test coverage report at `build/coverage.xml` and use it to write new Behave based unit tests to improve code coverage. Specifically, write Behave style unit tests that are descriptively named and specifically improves coverage on whichever file has the most uncovered lines by writing tests that will target the uncovered lines in the report. Once that is done rerun `nox -s coverage_report` to verify all tests pass and coverage is above >=97%. Only mark this as complete once coverage is >=97%, if not repeat this task as many times as is needed until coverage reaches >=97%. - [ ] Run `nox` (all default sessions, including benchmark), fix any errors if needed ensuring nox passes across **entire** code base, do not ignore any failure even if it seems unrelated to this commit, fix it. - [ ] Note: Safety profile enforcement is deferred; see Section 18 POST.safety. **Section**: ### Section 11: Security & Safety [WORKSTREAM F - Luis + Brent] **Status**: Open
freemo added this to the (deleted) milestone 2026-02-22 23:41:17 +00:00
freemo modified the milestone from (deleted) to v3.3.0 2026-02-23 00:07:07 +00:00
Author
Owner

Expected completion updated (Day 15 rebaseline): Day 35 / 2026-03-15 (previously Day 26 / 2026-03-06)

**Expected completion updated (Day 15 rebaseline):** Day 35 / 2026-03-15 (previously Day 26 / 2026-03-06)
freemo added the due date 2026-02-21 2026-02-23 18:41:51 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

2026-02-21

Blocks
#362 Epic: Security & Safety Hardening
cleveragents/cleveragents-core
Depends on
Reference
cleveragents/cleveragents-core#322
No description provided.