Skip to content

Stamp task source from authenticated caller for agent creates #787

Description

@lilyshen0722

Problem

POST /api/v1/tasks/:podId accepts source from the request body. An agent authenticated with a runtime token can therefore create a task while claiming source: "human". The field looks like provenance but is controlled by the monitored caller.

Fix

  • Force agent-authenticated task creation to persist source: "agent".
  • Preserve existing human-authenticated source overrides for GitHub/import workflows.
  • Add a service regression where an agent submits source: "human" and both the response and stored task report source: "agent".

Proof

Mutation requirement: removing the server-side stamp must fail only the adversarial agent assertion.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions