wunderforge / wunderforge/agenova
[EPIC E4] Tool and Model Gateway Enforcement
- Dominant language
- Go
- Stars
- 4
- Forks
- 0
- Avg merge
- 2d 13h
- Merged PRs (30d)
- 41
Description
## Outcome
a Running worker can use only the tool/resource/model capabilities present in its issued authority, while external provider credentials remain outside the worker.
## Delivery contract
- **Epic:** E4
- **Priority:** P0
- **Wave:** Wave B - Governed execution
- **Milestone:** Mid-term - Governed Vertical Slice
- **Area:** area:gateway
## Completion evidence
one allowed Tool call and one allowed Model call occur; all named denial cases produce no external call and are ready to be recorded as facts.
## Child delivery
Implementation tickets are attached as native GitHub sub-issues. Closing child PRs is not sufficient: this Epic closes only when the completion evidence above is reproducible.
## Product constraints
- Preserve the claim-scoped, backend-neutral architecture contract.
- Do not broaden this Epic into deferred platform work.
- Gate failures must narrow scope or repair the harness before more implementation is added.
Contributor guide
Research direction
Start with the native GitHub sub-issues attached to this epic and trace how the gateway enforces issued tool, resource, and model authority. Reproduce one allowed Tool call and one allowed Model call, then verify each named denial case makes no external call and can be recorded as a fact. Keep the backend-neutral, claim-scoped contract unchanged.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- authorization, backend
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100