Skip to content

Add audit metadata and privacy tests for context memory #268

@michaelmwu

Description

@michaelmwu

Parent: #265

Goal

Add audit metadata and security/privacy tests for context and memory behavior.

Scope

  • Track context sources per operation in agent_context_sources or equivalent.
  • Include context-source IDs in agent plan/audit payloads.
  • Redact sensitive values in audit output.
  • Add tests for:
    • prompt injection in retrieved messages
    • private-channel leaks
    • response destination visibility
    • deleted/expired memory facts
    • unauthorized cross-user memory reads
    • memory writes without confirmation
    • tool calls still being re-authorized after context retrieval

Acceptance criteria

  • Every agent operation records which context/memory sources were used.
  • Audit payloads include source refs without leaking sensitive bodies unnecessarily.
  • Prompt-injection tests prove retrieved content cannot grant scopes, change tools, or bypass confirmations.
  • Privacy/security regressions fail tests.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions