Personal-agent permissions need requester identity plus limits on returned data
maritime_sh · reddit · 2026-10-05
While open-sourcing their personal-agent app Open Instinct, the author got a key critique: a tool allowlist alone doesn't solve the confused-deputy problem—an agent permitted to call a tool can still return more data than the requester should see.
Using agent-to-agent scheduling as an example: a requester needs only free/busy intervals, but a calendar integration may also expose event titles, attendees, and descriptions. Handing the model everything and asking it to be discreet is a different boundary than returning only permitted fields from the tool wrapper.
Three separate checks are proposed:
- Derive requester identity from verified transport identity, not message text ('I'm the owner' should not affect this check)
- Authorize the operation per requester
- Constrain returned fields before they reach a lower-trust conversation (a successful tool call should not bypass this)
Regression suggestions: run the same scheduling request as owner/friend/stranger with an impersonation instruction embedded, inspect both tool arguments and returned data, and test revoking a grant mid-conversation. The author notes these are proposed checks, not claims the beta solves everything. Code: https://github.com/mariagorskikh/open-instinct
More from coding & agent
- GLM vs Qwen tool calling differences force separate handlers in Codex proxy — TheZachMueller · 2026-10-05
- Why running third-party models in Codex needs a tool-calling proxy layer — TheZachMueller · 2026-10-05
- Dev says nearly all his web searches now run through personal agents as web goes headless — illscience · 2026-10-05
- RelayDesk connects Claude to your own computers and VMs via MCP — whateverxp · 2026-10-05
- Musk amplifies "zero human company" run by a Grok bot as CEO — elonmusk · 2026-10-05
- The AI Checkout Demo Everyone Wants: Agent Retries Without Double-Charging — HaktanSuren · 2026-10-05