Security and Audits
Permissions, validation, audit trails, known gaps, and recoverable workflows.
A local agent architecture needs security to be part of the workflow design. Tools, agents, artifacts, and runtime services should be explicit about what they can do, what they record, and how failures are reviewed.
Principles
- Use least privilege for tools, files, and external adapters.
- Require explicit confirmation for destructive operations.
- Keep agent, tool, and runtime boundaries visible.
- Record artifacts so outputs can be traced to inputs.
- Review generated artifacts before they become part of a workflow.
- Document gaps, degradations, and recovery steps.
Audits
The audit layer contains ecosystem reviews. A useful audit answers:
- What was reviewed?
- What works?
- What fails?
- What is degraded?
- Which actions are priorities?
Typical Findings
Observed finding types include:
- unavailable external dependencies;
- missing packages;
- inaccessible web sources;
- partially functional flows;
- file permissions that should be hardened;
- mocks still present where real data is expected;
- differences between documented state and real state.
Severity Model
| Level | Meaning |
|---|---|
| Critical | Blocks functionality or creates unsafe data exposure. |
| High | Breaks an important flow or prevents verification. |
| Medium | Degrades quality, coverage, or reliability. |
| Low | Pending improvement, cleanup, or documentation. |
Validation Review
- Verify the command or agent boundary before running a workflow.
- Confirm that permissions match the task being performed.
- Review generated artifacts before reuse.
- Check dependency state and external service availability.
- Record partial failures instead of flattening them into success.
- Keep recovery steps close to the workflow they support.
Learning
In agent architecture, security is not only an API concern. It is also a property of tool contracts, permissions, artifact review, repeatable validation, and recoverable failure modes.