Skip to content

Add Agent Containment and Owner Authorization profile (ACP) with SAF-M-75 through SAF-M-82 - #235

Open
soltrinox wants to merge 1 commit into
secure-agentic-framework:mainfrom
soltrinox:feat/agent-containment-owner-authorization
Open

soltrinox wants to merge 1 commit into
secure-agentic-framework:mainfrom
soltrinox:feat/agent-containment-owner-authorization

Conversation

@soltrinox

Copy link
Copy Markdown

No description provided.

Introduce the ACP deployment requirement profile: 28 contextual
attack-assessment items mapped to existing SAF techniques, 34 traceable
requirements with planned acceptance tests, and eight proposed mitigations
(SAF-M-75 through SAF-M-82) grouped by enforcement boundary.

Add a generator and a metadata validator for the profile, 15 regression
tests, and wire both into the technique-research workflow.

Canonical technique IDs, names, scope, lifecycle, evidence status, and
detection maturity are unchanged; only proposed mitigation references are
added to the framework model. Repository checks validate catalog integrity
and cross-references only. No deployment acceptance test, secure runtime,
cryptographic verifier, or telemetry detector is implemented or field
validated by this change.

Signed-off-by: soltrinox <soltrinox@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
@soltrinox

Copy link
Copy Markdown
Author

Maintainers,

This pull request has been open since 16 September 2026 and has not been reviewed or merged. We are still waiting for a decision on whether you will accept it into main.

#235

The change adds the proposed Agent Containment and Owner Authorization profile (profiles/agent-containment/) and mitigations SAF-M-75 through SAF-M-82. Catalog integrity and repository integration checks are included. It does not add canonical SAF techniques, and it does not include a field-validated runtime.

Head commit ee200dd is one commit, 33 files, and the DCO check passed. The profile is public on soltrinox:feat/agent-containment-owner-authorization and is not on upstream main.

Please review and either accept the pull request or tell us what must change before it can be merged.

@soltrinox

Copy link
Copy Markdown
Author

@soltrinox soltrinox mentioned this pull request Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant