Skip to content

[OpenSpec] tool-scope-security-default #344

Description

@github-actions

⚠️ OpenSpec-managed issue — this content is automatically synced
from the openspec/ directory. Manual edits will be overwritten on next sync.

Artifacts

Specs

Tasks

  • Delete HERMIQ_LEGACY_UNSCOPED_TOOLS and its branch
  • Delete applyDefaultDeny(), orphaned once the branch goes
  • Keep isWriteOrDestructive() — wildcard expansion and the approval gate still use it
  • Update the tests currently opting into the flag to exercise classification another way
  • Keep the assertion that an unconfigured agent is tool-less but NOT reported as broken
  • Add a report listing agents whose tools is null or empty
  • The report MUST NOT modify them

Design

See design.md for technical design details.


Synced from openspec/changes/tool-scope-security-default by OpenSpec workflow
App: hermiq

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    openspecManaged by OpenSpec workflowopenspec:tasksOpenSpec phase: Tasks

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions