Problem
POST /api/v1/tasks/:podId accepts source from the request body. An agent authenticated with a runtime token can therefore create a task while claiming source: "human". The field looks like provenance but is controlled by the monitored caller.
Fix
- Force agent-authenticated task creation to persist
source: "agent".
- Preserve existing human-authenticated source overrides for GitHub/import workflows.
- Add a service regression where an agent submits
source: "human" and both the response and stored task report source: "agent".
Proof
Mutation requirement: removing the server-side stamp must fail only the adversarial agent assertion.
Problem
POST /api/v1/tasks/:podIdacceptssourcefrom the request body. An agent authenticated with a runtime token can therefore create a task while claimingsource: "human". The field looks like provenance but is controlled by the monitored caller.Fix
source: "agent".source: "human"and both the response and stored task reportsource: "agent".Proof
Mutation requirement: removing the server-side stamp must fail only the adversarial agent assertion.