The hole in contract-based AI agent governance: devs can silently rewrite the contract
Trout_dev · reddit · 2026-10-05
A developer building a runtime governance layer for AI agents highlights three unsolved problems and his fixes:
- Contract mutability: a developer can silently delete an approval point from a contract.yaml; audit logs then reference a version that no longer exists. Fix: cryptographically seal each contract on load (ContractTamperError on any change) plus a versioned append-only registry so you can always answer "what contract governed this agent yesterday at 3pm?"
- Contractless agents: dynamically spawned subagents and wrapped third-party agents have no contract file. Fix: programmatic declarations at runtime via ContractEnforcer.fromdeclaration with identical enforcement; anything undeclared defaults to read-only with per-action approval.
- The gate is opt-in: an agent can simply not call it. Fix: a gateway layer exclusively holding all credentials, plus a CI lint that fails builds if any file outside the gateway imports the raw client — three independent barriers.
He invites discussion on contract versioning and governing dynamically spawned agents in production.
More from coding & agent
- Ruff Author Slams pnpm Over Disabling Private Vulnerability Reporting — charliermarsh · 2026-10-05
- Ruff Author Urges pnpm Not to Disable Private Vulnerability Reporting Without Alternative — charliermarsh · 2026-10-05
- Researchers Trace Agent Swarm Scanning Amap Back to Tencent, Report Coming — austinc3301 · 2026-10-05
- pnpm's zkochan: Spam Forced the Change, Real Bugs Still Fixed Within a Day — zkochan · 2026-10-05
- Your agent's reliability problem isn't the model — it's the missing harness — bgoncalves · 2026-10-05
- ilo pivots to X-to-Markdown tool with CLI/MCP for agents, from $0.002 per post — iannuttall · 2026-10-05