aws-samples / aws-samples/sample-autonomous-cloud-coding-agents
agent: block integration trigger labels from agent write-back
- Dominant language
- TypeScript
- Stars
- 143
- Forks
- 46
- Avg merge
- 3d 9h
- Merged PRs (30d)
- 20
Description
### Component
Agent (Python runtime)
### Describe the feature
Prevent the agent from setting **integration trigger labels** that would re-fire webhooks and spawn duplicate tasks (infinite loop / cost blow-up).
Known trigger surfaces today:
| Integration | Default trigger | Set by |
|-------------|-----------------|--------|
| Jira | `bgagent` label | User / automation |
| Linear | `bgagent` label | User / automation |
| Future GitHub label channel | TBD (e.g. `bgagent`) | User only |
Enforcement:
1. **PreToolUse / Cedar hard-deny** on issue-write tools when `labels` includes the configured trigger label for that task's source integration.
2. **Allowlist** of agent-set labels: progress/status labels only (e.g. `agent:implementing`, `agent:pr-created`, `agent:error`) — configurable per integration in Blueprint.
3. **Fail-closed** if task metadata does not include `trigger_label` when issue-write tools are allowed.
### Use case
Linear and Jira processors fire on **label added** events. If the agent posts comments and accidentally (or via prompt injection) re-applies the trigger label, the platform may enqueue another full task against the same issue — unbounded cost and race conditions.
### Proposed solution
1. Extend task hydration context with `trigger_label` and `allowed_agent_labels` from repo Blueprint / integration mapping.
2. Add Cedar policy module `builtin/trigger_label_governance` or extend deterministic PreToolUse regex guards for MCP `update_issue` / label payloads.
3. Mirror check in Jira/Linear outbound clients if agents call REST directly.
4. Tests: agent policy tests + handler tests for webhook processor dedup (label must be *newly added*, not re-saved — already true for Jira; document same for agent writes).
5. Document operator guidance: restrict who can apply trigger labels on public repos.
### Other information
- Related: `docs/guides/JIRA_SETUP_GUIDE.md`, Linear mapping construct, #389 (platform trigger expansion), #230 (event governance RFC).
- Complements webhook dedup logic in `jira-webhook-processor.ts` / `linear-webhook-processor.ts` (ingress dedup does not stop agent write-back).
- Out of scope: changing default trigger label names (backward compatible).
### Acknowledgements
- [x] I may be able to implement this feature
- [ ] This might be a breaking change
Contributor guide
Research direction
Start with the PreToolUse/Cedar issue-write enforcement and the named jira-webhook-processor.ts and linear-webhook-processor.ts paths. Review the related JIRA_SETUP_GUIDE.md, Linear mapping construct, and agent policy and handler tests. Done means trigger labels are blocked from agent writes, allowed labels remain configurable, missing trigger metadata fails closed, and webhook dedup behavior is covered.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python, typescript
- Domain
- backend-api-design, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100