aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

agent: block integration trigger labels from agent write-back

Offen
#550 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
adapters agent-runtime enhancement P2 security
Vorherrschende Sprache
TypeScript
Sterne
143
Forks
46
Ø Merge
3 T. 10 Std.
Gemergte PRs (30 T.)
24

Beschreibung

### Component

Agent (Python runtime)

### Describe the feature

Prevent the agent from setting **integration trigger labels** that would re-fire webhooks and spawn duplicate tasks (infinite loop / cost blow-up).

Known trigger surfaces today:

| Integration | Default trigger | Set by |
|-------------|-----------------|--------|
| Jira | `bgagent` label | User / automation |
| Linear | `bgagent` label | User / automation |
| Future GitHub label channel | TBD (e.g. `bgagent`) | User only |

Enforcement:

1. **PreToolUse / Cedar hard-deny** on issue-write tools when `labels` includes the configured trigger label for that task's source integration.
2. **Allowlist** of agent-set labels: progress/status labels only (e.g. `agent:implementing`, `agent:pr-created`, `agent:error`) — configurable per integration in Blueprint.
3. **Fail-closed** if task metadata does not include `trigger_label` when issue-write tools are allowed.

### Use case

Linear and Jira processors fire on **label added** events. If the agent posts comments and accidentally (or via prompt injection) re-applies the trigger label, the platform may enqueue another full task against the same issue — unbounded cost and race conditions.

### Proposed solution

1. Extend task hydration context with `trigger_label` and `allowed_agent_labels` from repo Blueprint / integration mapping.
2. Add Cedar policy module `builtin/trigger_label_governance` or extend deterministic PreToolUse regex guards for MCP `update_issue` / label payloads.
3. Mirror check in Jira/Linear outbound clients if agents call REST directly.
4. Tests: agent policy tests + handler tests for webhook processor dedup (label must be *newly added*, not re-saved — already true for Jira; document same for agent writes).
5. Document operator guidance: restrict who can apply trigger labels on public repos.

### Other information

- Related: `docs/guides/JIRA_SETUP_GUIDE.md`, Linear mapping construct, #389 (platform trigger expansion), #230 (event governance RFC).
- Complements webhook dedup logic in `jira-webhook-processor.ts` / `linear-webhook-processor.ts` (ingress dedup does not stop agent write-back).
- Out of scope: changing default trigger label names (backward compatible).

### Acknowledgements

- [x] I may be able to implement this feature
- [ ] This might be a breaking change

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit der Durchsetzung für issue-write in PreToolUse/Cedar und den genannten Pfaden jira-webhook-processor.ts und linear-webhook-processor.ts. Prüfe die zugehörige JIRA_SETUP_GUIDE.md, das Linear-Mapping-Konstrukt sowie die Tests für Agentenrichtlinie und Handler. Erledigt bedeutet, dass Trigger-Labels bei Writes von Agents blockiert werden, zulässige Labels konfigurierbar bleiben, fehlende Trigger-Metadaten standardmäßig abgelehnt werden und das Webhook-Deduplizierungsverhalten abgedeckt ist.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python, typescript
Bereich
backend-api-design, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
38/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.