aws-samples / aws-samples/sample-autonomous-cloud-coding-agents

agent: block integration trigger labels from agent write-back

Abierto
#550 0 comentarios 0 reacciones 0 asignados Ver en GitHub
adapters agent-runtime enhancement P2 security
Lenguaje dominante
TypeScript
Estrellas
143
Forks
46
Merge medio
3 d 10 h
PR fusionados (30 d)
24

Descripción

### Component

Agent (Python runtime)

### Describe the feature

Prevent the agent from setting **integration trigger labels** that would re-fire webhooks and spawn duplicate tasks (infinite loop / cost blow-up).

Known trigger surfaces today:

| Integration | Default trigger | Set by |
|-------------|-----------------|--------|
| Jira | `bgagent` label | User / automation |
| Linear | `bgagent` label | User / automation |
| Future GitHub label channel | TBD (e.g. `bgagent`) | User only |

Enforcement:

1. **PreToolUse / Cedar hard-deny** on issue-write tools when `labels` includes the configured trigger label for that task's source integration.
2. **Allowlist** of agent-set labels: progress/status labels only (e.g. `agent:implementing`, `agent:pr-created`, `agent:error`) — configurable per integration in Blueprint.
3. **Fail-closed** if task metadata does not include `trigger_label` when issue-write tools are allowed.

### Use case

Linear and Jira processors fire on **label added** events. If the agent posts comments and accidentally (or via prompt injection) re-applies the trigger label, the platform may enqueue another full task against the same issue — unbounded cost and race conditions.

### Proposed solution

1. Extend task hydration context with `trigger_label` and `allowed_agent_labels` from repo Blueprint / integration mapping.
2. Add Cedar policy module `builtin/trigger_label_governance` or extend deterministic PreToolUse regex guards for MCP `update_issue` / label payloads.
3. Mirror check in Jira/Linear outbound clients if agents call REST directly.
4. Tests: agent policy tests + handler tests for webhook processor dedup (label must be *newly added*, not re-saved — already true for Jira; document same for agent writes).
5. Document operator guidance: restrict who can apply trigger labels on public repos.

### Other information

- Related: `docs/guides/JIRA_SETUP_GUIDE.md`, Linear mapping construct, #389 (platform trigger expansion), #230 (event governance RFC).
- Complements webhook dedup logic in `jira-webhook-processor.ts` / `linear-webhook-processor.ts` (ingress dedup does not stop agent write-back).
- Out of scope: changing default trigger label names (backward compatible).

### Acknowledgements

- [x] I may be able to implement this feature
- [ ] This might be a breaking change

Guía de contribución

Abrir la guía de contribución

Línea de trabajo

Comienza con la aplicación de la restricción de issue-write en PreToolUse/Cedar y con las rutas indicadas jira-webhook-processor.ts y linear-webhook-processor.ts. Revisa la JIRA_SETUP_GUIDE.md relacionada, la construcción de mapeo de Linear y las pruebas de la política del agente y del handler. Se considera terminado cuando las etiquetas de activación están bloqueadas para los writes del agente, las etiquetas permitidas siguen siendo configurables, la ausencia de metadatos de activación falla de forma segura y el comportamiento de deduplicación del webhook está cubierto.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python, typescript
Área
backend-api-design, security
Tipo de issue
Nueva funcionalidad
Dificultad
5/5
Tiempo estimado
Más de una semana
Estado de actividad
Tranquilo
Claridad
Bastante claro
Aptitud para principiantes
38/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.