wunderforge / wunderforge/agenova

[EPIC E4] Tool and Model Gateway Enforcement

Open
#8 0 comments 0 reactions 0 assignees View on GitHub
area:gateway priority:p0 type:epic
Dominant language
Go
Stars
4
Forks
0
Avg merge
2d 13h
Merged PRs (30d)
41

Description

## Outcome

a Running worker can use only the tool/resource/model capabilities present in its issued authority, while external provider credentials remain outside the worker.

## Delivery contract

- **Epic:** E4
- **Priority:** P0
- **Wave:** Wave B - Governed execution
- **Milestone:** Mid-term - Governed Vertical Slice
- **Area:** area:gateway

## Completion evidence

one allowed Tool call and one allowed Model call occur; all named denial cases produce no external call and are ready to be recorded as facts.

## Child delivery

Implementation tickets are attached as native GitHub sub-issues. Closing child PRs is not sufficient: this Epic closes only when the completion evidence above is reproducible.

## Product constraints

- Preserve the claim-scoped, backend-neutral architecture contract.
- Do not broaden this Epic into deferred platform work.
- Gate failures must narrow scope or repair the harness before more implementation is added.

Contributor guide

Open the contributing guide

Research direction

Start with the native GitHub sub-issues attached to this epic and trace how the gateway enforces issued tool, resource, and model authority. Reproduce one allowed Tool call and one allowed Model call, then verify each named denial case makes no external call and can be recorded as a fact. Keep the backend-neutral, claim-scoped contract unchanged.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authorization, backend
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.