Skip to content

docs(vercel_ai): explain privileged tool approval rule - #82

Open
CodingWCal wants to merge 3 commits into
trustabl:mainfrom
CodingWCal:justin/vercel-tool-approval
Open

docs(vercel_ai): explain privileged tool approval rule#82
CodingWCal wants to merge 3 commits into
trustabl:mainfrom
CodingWCal:justin/vercel-tool-approval

Conversation

@CodingWCal

@CodingWCal CodingWCal commented Aug 24, 2026

Copy link
Copy Markdown

Change

Adds the VAI-013 threat model and rationale for Vercel AI tools that shell out or evaluate dynamic code without a tool-level needsApproval gate.

Scope boundary

AI SDK 7 moved approval to call or agent-level toolApproval. The current scanner cannot correlate that setting to a tool, so the document records it as a manual-review limitation.

Validation

  • Front matter matches the production YAML
  • python tools/check_rulebook.py adds no new errors
  • Known baseline errors: OAI-112, PYD-106

Companion PRs

Team

Justin (@jj-javascript): rationale author
Calvin: integration, SDK 7 limitation correction, and final documentation QA
Karlee (@kperpignant): consulting partner, threat model, and QA review (credited contributor)

@CodingWCal CodingWCal changed the title draft: docs(vercel_ai): explain privileged tool approval rule docs(vercel_ai): explain privileged tool approval rule Aug 24, 2026
@CodingWCal
CodingWCal marked this pull request as ready for review August 24, 2026 19:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants