Lumen
Security

Network and tool policy

Authorize exact product tools and destinations without granting general provider access.

Outcome

Each attempt has one fixed local sandbox harness and can call only the named, schema-validated trusted tools and network destinations inside its current policy, budget, approval, and generation.

Prerequisites

Classify each trusted tool as read, write, execute, external side effect, credentialed, or destructive. Define argument constraints, data destinations, approval mode, rate/cost limit, and idempotency semantics. Treat runner-local read/list/search/write/edit/bash/python/subagents.delegate separately: they have no provider credential or canonical authority and are constrained by the sandbox plus the numeric limits in the frozen runtime manifest.

Steps

  1. Resolve the execution profile into its fixed local tool set, then generate only the allowed trusted definitions for the attempt. Planning is limited to local read/list/search plus research.inspect, search_web, fetch_source, tasks.list, and tasks.revise_plan.
  2. Freeze local IDs and limits, trusted definition digests and remote-MCP provenance, context digest, build/image/environment/Pi/model/reasoning identity, and subagent caps in the attempt runtime manifest.
  3. Bind each trusted capability to workspace, project, run, attempt, generation, tool IDs, normalized arguments, expiry, nonce, budget, audience, and policy version.
  4. Consume one-use authority atomically at the trusted gateway.
  5. Execute credentialed side effects outside the sandbox.
  6. Record the exact external request identity and reconcile ambiguity before retry.

Network denial must be effective at the selected provider/class/image, not merely written in configuration. Package registries and general internet access remain denied from attempts. Reviewed images carry dependencies, while web, connector, and remote-MCP work uses the trusted Lumen routes; a task cannot add direct egress authority.

Verify

Reject forged, replayed, expired, revoked, cross-attempt, cross-workspace, over-budget, approval-mismatched, and argument-mutated grants. Reject manifest/tool-definition drift on resume. Prove local tool path/byte/time limits and reserved context-path rejection separately; do not treat mode 0400 as a hard boundary against same-UID bash. Direct provider and arbitrary host canaries must fail while the scoped Lumen inference/trusted-tool routes succeed.

Recover

On unexpected egress or tool authority, pause the attempt and revoke its generation. Rotate any affected credential, reconcile external mutations by idempotency identity, and retain the attempt as failed diagnostic evidence.

Next task

Protect secrets.

On this page