Personal-agent permissions need requester identity plus limits on returned data

maritime_sh · reddit · 2026-10-05

While open-sourcing their personal-agent app Open Instinct, the author got a key critique: a tool allowlist alone doesn't solve the confused-deputy problem—an agent permitted to call a tool can still return more data than the requester should see.

Using agent-to-agent scheduling as an example: a requester needs only free/busy intervals, but a calendar integration may also expose event titles, attendees, and descriptions. Handing the model everything and asking it to be discreet is a different boundary than returning only permitted fields from the tool wrapper.

Three separate checks are proposed:

Regression suggestions: run the same scheduling request as owner/friend/stranger with an impersonation instruction embedded, inspect both tool arguments and returned data, and test revoking a grant mid-conversation. The author notes these are proposed checks, not claims the beta solves everything. Code: https://github.com/mariagorskikh/open-instinct

Original post →

More from coding & agent

coding & agent channel →