Add Agent Containment and Owner Authorization profile (ACP) with SAF-M-75 through SAF-M-82 - #235
Conversation
Introduce the ACP deployment requirement profile: 28 contextual attack-assessment items mapped to existing SAF techniques, 34 traceable requirements with planned acceptance tests, and eight proposed mitigations (SAF-M-75 through SAF-M-82) grouped by enforcement boundary. Add a generator and a metadata validator for the profile, 15 regression tests, and wire both into the technique-research workflow. Canonical technique IDs, names, scope, lifecycle, evidence status, and detection maturity are unchanged; only proposed mitigation references are added to the framework model. Repository checks validate catalog integrity and cross-references only. No deployment acceptance test, secure runtime, cryptographic verifier, or telemetry detector is implemented or field validated by this change. Signed-off-by: soltrinox <soltrinox@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
|
Maintainers, This pull request has been open since 16 September 2026 and has not been reviewed or merged. We are still waiting for a decision on whether you will accept it into main. The change adds the proposed Agent Containment and Owner Authorization profile (profiles/agent-containment/) and mitigations SAF-M-75 through SAF-M-82. Catalog integrity and repository integration checks are included. It does not add canonical SAF techniques, and it does not include a field-validated runtime. Head commit ee200dd is one commit, 33 files, and the DCO check passed. The profile is public on soltrinox:feat/agent-containment-owner-authorization and is not on upstream main. Please review and either accept the pull request or tell us what must change before it can be merged. |
No description provided.