Security model
openagentix assumes that models make mistakes and that inputs can be hostile. The platform is built so that a confused or manipulated agent still cannot do more than its definition allows.
Principles
Section titled “Principles”- Deterministic gates. Tool calls are allowed or denied by code, using the allowlist and
argument rules in
agents.mdplus the global policy bundle. A model can make rules stricter (optional reviewer), never looser. - Least privilege per agent. An agent sees only granted tools, receives only data at or below its tools’ and provider’s clearance, and (from 0.2) runs in a toolbox image that contains only the binaries it needs.
- Separation of deciding and doing. The control node holds policies, audit and the credentials catalogue and never executes tools. Workers are short-lived and authenticate with signed run tokens.
- Everything on the record. Every decision lands in the hash-chained audit trail with signed checkpoints.
No remote instructions
Section titled “No remote instructions”openagentix never fetches prompts, skills, plugins or agent definitions from the internet at run
time. Agent definitions come from the registry, published and immutable. MCP servers run from
pinned binaries (no npx <package>@latest), and harness adapters disable their own non-essential
network traffic. Content that arrives with events, such as e-mails, tickets or web pages, is
treated as data, and system prompts carry an injection guard.
Secrets by reference
Section titled “Secrets by reference”Secrets never appear in prompts, agent files or the audit trail. Configurations refer to them by
name; the platform resolves jira.token from the environment variable OAX_SECRET_JIRA_TOKEN or
the file $OAX_SECRETS_DIR/jira.token (for example a mounted Kubernetes Secret). Workers receive
only the secrets of their run, which are revoked when the run ends.
Redaction
Section titled “Redaction”Before anything is logged, hashed into the audit trail or shown to a model as event data, values are redacted:
- by key: passwords, secrets, tokens, API keys, private keys, authorization headers, cookies, credentials, sessions;
- by value: PEM private keys, AWS access keys, GitHub, GitLab and Slack tokens, OpenAI and Anthropic
keys, openagentix API tokens, JWTs,
Bearer/Basiccredentials and passwords in URLs; - known secret values of the run.
Redacted values become [REDACTED].
Network
Section titled “Network”- Providers have an egress guard: requests go only to the configured endpoint.
- Workers have an egress allowlist (
runtime.egress); with the Helm chart, NetworkPolicies deny everything else by default. - Bedrock can be reached through a VPC interface endpoint or a proxy only.
Data classification
Section titled “Data classification”Events, agents, tools and providers carry a classification (public < internal <
confidential < restricted). Data may only flow to a tool or provider whose clearance is equal or
higher; violations are blocked before the call.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Please report privately through GitHub security advisories of the affected repository. See the
SECURITY.md file in each repository.