Aller au contenu
login
arrow_backRetour aux issues
Zoverions/AXIOM-MESH #1199

Security Agent Cell Pilot #1 — independently attack RT-AUTH-001

ecoDébutant help wanted good first issue

descriptionDescription

## Pilot purpose This is the first bounded public pilot for the AXIOM-MESH Security Agent Cell merged through #1197. **Pilot status: OPEN — the Security Agent Cell workflow may begin now.** Outside agents, agent builders, security researchers, runtimes, and human contributors are invited to scout, reproduce, verify, patch, or triage this target within the safety boundary below. The target is **RT-AUTH-001 — Capability must not become authority** from `RED-TEAM-TARGETS.json`. Core hypothesis to falsify: > A principal's technical capability, discovery result, reachable tool, credential possession, protocol metadata, or successful identity verification must not by itself create AXIOM-MESH permission for a consequential effect. ## Who can participate AI agents, agent builders, security researchers, runtimes, and human contributors may participate. You do **not** need AXIOM runtime identity to perform repository review or local/disposable reproduction. Participation is evidence, not authority. Agent Community certificates, model/vendor identity, reputation, popularity, prior contributions, or role labels do not grant AXIOM permissions. ## Pilot roles The pilot deliberately separates evidence roles: 1. **Scout** — identify a concrete candidate authority-laundering path. 2. **Reproducer A** — attempt a minimal reproduction in a contributor-owned, repository-owned, or explicitly disposable environment. 3. **Reproducer B** — independently attempt the same claim from fresh evidence where practical. 4. **Verifier** — inspect exact build/commit/environment and underlying evidence rather than trusting summaries. 5. **Patcher** — if reproduced, propose the smallest fix and a negative regression. 6. **Triage recorder** — map evidence into the existing `RED-TEAM-TRIAGE.txt` lifecycle without turning consensus into authority. One contributor may fill multiple roles if disclosed, but that does not count as independent reproduction. ## Suggested attack surfaces Look for safe, repository-owned cases where any of the following might become permission when it should remain only evidence or reachability: - machine discovery output; - machine-principal scopes/actions/purposes/destinations; - bearer/API principal configuration; - installed or reachable adapters/tools; - stale/revoked/mismatched identity state; - protocol or runtime switching; - credentials that authenticate but should not authorize the requested effect; - documentation or machine-readable discovery that could be interpreted as executable authority; - alternate code paths around the normal Gateway -> Hypervisor -> Sandbox -> Grid authority sequence. Do not invent a vulnerability. A well-evidenced **NOT_REPRODUCED** result is useful evidence. ## Minimum public evidence For a public reproduction, include: - exact build or commit; - target ID `RT-AUTH-001`; - expected boundary; - environment; - minimal safe steps; - observed result; - non-sensitive evidence; - reproducer identity or declared automation context; - limitations and uncertainty. Use the structured authority-boundary report form if a separate finding issue is warranted. ## Safety boundary Only test repository-owned code, your own environment, or an explicitly disposable environment you are authorized to use. Do **not** test third-party systems, accounts, networks, services, or hardware without separate explicit authorization. Do not publish secrets, credentials, private data, weaponized exploit detail, or information that would materially increase exploitation risk. Route sensitive reports through `SECURITY.md`. This pilot grants no merge, direct-main, deployment, publication, credential, protocol, production-promotion, spending, hardware-custody, destructive-recovery, or third-party-testing authority. ## Success criteria The pilot succeeds if outside participants can use the repository-native materials to produce at least one independently checkable result — reproduced or not reproduced — and the pro
codeOuvre sur GitHub