Skip to content

open-coder-ai/protect-agent-config

v0.0.1Apache-2.0

Guard against an agent hand-editing its own guardrails. Agent instruction files (AGENTS.md and the per-agent wrappers), permission files (.claude/settings.json, .mcp.json) and vendored enforcement (.chock/bin/, .chock/compiled/) define what the agent may do -- so a shell command that rewrites them is the agent modifying its own authority (MITRE ATLAS AML.T0081; the AIVSS self-modification factor). The guard refuses shell write-commands targeting those paths; reads pass, and regeneration through chock sync passes because the tool writes them itself rather than through shell editing. Best-effort and deliberately coarse: a compound command that both reads a protected file and writes elsewhere may be refused -- rewrite it in two steps. Escape for a human-approved change: include 'chock: approved-config-change' in the command.

What this package declares

The file a client reads when it loads this plugin, exactly as this revision carries it.

plugin.json
{
  "$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
  "name": "protect-agent-config",
  "version": "0.0.1",
  "description": "Guard against an agent hand-editing its own guardrails. Agent instruction files (AGENTS.md and the per-agent wrappers), permission files (.claude/settings.json, .mcp.json) and vendored enforcement (.chock/bin/, .chock/compiled/) define what the agent may do -- so a shell command that rewrites them is the agent modifying its own authority (MITRE ATLAS AML.T0081; the AIVSS self-modification factor). The guard refuses shell write-commands targeting those paths; reads pass, and regeneration through `chock sync` passes because the tool writes them itself rather than through shell editing. Best-effort and deliberately coarse: a compound command that both reads a protected file and writes elsewhere may be refused -- rewrite it in two steps. Escape for a human-approved change: include 'chock: approved-config-change' in the command.",
  "author": {
    "name": "chock-core"
  },
  "repository": "https://github.com/open-coder-ai/chock-catalog",
  "license": "Apache-2.0",
  "keywords": [
    "chock",
    "policy-as-code",
    "rule",
    "advise",
    "{'control': 'asi03', 'coverage': 'partial', 'note': 'blocks shell self-modification of agent permission and instruction files; identity design and grant scoping remain advisory'}"
  ],
  "extensions": {
    "io.github.open-coder-ai": {
      "manifest": "manifest.yaml",
      "artifact": "rule",
      "enforcement": "advise",
      "coverage_without_chock": "advisory"
    }
  }
}

Client extensions

Data this package carries for particular clients. The directory lists the clients named and never reads what is addressed to them.

  • io.github.open-coder-ai