Skip to content

What stops an agent on a domain-specific server changing production DNS or Workers? #485

Description

@javmann100

Genuine question, not a hypothetical. The domain-specific servers give an agent focused tools over a real account; the code-mode server gives it broad API coverage. Either way, when an agent asks for something ten times larger than usual, say a DNS change on the production zone or a deploy to every Worker, what stops it today: the API token's scope, a prompt, or noticing afterwards?

I am building mnki, an open-source trust layer with a fourth answer: bounded authority checked outside the model before the call runs (this agent, for this principal, these zones, these operations, until this date), a human approval on a phone for the cases that deserve one, and a signed record of every decision. It runs on Workers itself and sits in front of an MCP server as a proxy or gateway, so it works with yours unchanged.

Twenty minutes to hear how you think about per-agent limits above token scopes would help me; a reply here is fine too. Reference implementation, Apache-2.0: https://github.com/MNKIAgentOS/agent-trust; integration paths: https://mnki.com/docs/integrations. Thank you for splitting the servers by domain; the smaller surfaces are the ones enterprises can reason about.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions