Skip to content

Security: add guarded OpenAI tool-calling reference - #2

Merged
blocksifrdev merged 7 commits into
mainfrom
security/openai-tool-guardrail-reference
Aug 20, 2026
Merged

blocksifrdev merged 7 commits into
mainfrom
security/openai-tool-guardrail-reference

Conversation

@blocksifrdev

Copy link
Copy Markdown
Contributor

Adds a non-production IEG reference implementation for model-generated tool calls.

What it establishes:

  • the model may propose an action but cannot grant itself authority
  • deterministic tool registry with exact per-tool policy
  • strict Pydantic v2 argument schemas with extra=forbid and strict typing
  • explicit host-supplied AuthorityContext
  • ALLOW / STEP_UP / DENY decisions before any downstream call
  • separate pre-execution DecisionReceipt and post-execution ExecutionReceipt
  • payload, decision and result hashing
  • no in-process signing key in the sample; production signing is explicitly external
  • OpenAI Responses API adapter using strict function schemas and function_call_output
  • deterministic tests for allowed reads, protected-action step-up, schema injection, unknown tools and type coercion
  • CI job for the reference code

Important corrections to the earlier guardrail sketch:

  • does not claim prompt-injection immunity
  • does not treat Pydantic frozen=True as immutable audit storage
  • does not use a simple HIGH/MEDIUM/LOW hierarchy as authority
  • does not mint an execution receipt before execution actually occurs
  • does not allow the model or user prompt to create its AuthorityContext

This remains public reference code under the repository's Apache 2.0 reference-code licensing. Paid runtime enforcement remains separate.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@blocksifrdev
blocksifrdev merged commit df8da12 into main Aug 20, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant