Skip to main content

AgentFacts

Struct AgentFacts 

Source
pub struct AgentFacts {
    pub name: String,
    pub role: String,
    pub exec: ExecFacts,
    pub writes: Vec<PathBuf>,
    pub net: NetworkOutboundMode,
    pub skills: Vec<String>,
    pub model_ref: String,
    pub effort: Option<Effort>,
    pub running: bool,
    pub drift: bool,
}
Expand description

One agent, as the kernel and the profile describe it.

Fields§

§name: String§role: String

profile.role, falling back to a non-boilerplate persona.description. Empty means nobody has said what this agent is for.

§exec: ExecFacts§writes: Vec<PathBuf>§net: NetworkOutboundMode§skills: Vec<String>§model_ref: String§effort: Option<Effort>

Per-turn effort from the profile. None means unset — which is the API default (high), not “no effort”; mur agent who says so explicitly because the difference is the whole point.

§running: bool§drift: bool

profile.yaml (or sys_prompt.md) was edited after the running process started, so the live agent is NOT what this index describes. See [started_after_edits].

Implementations§

Source§

impl AgentFacts

Source

pub fn can_exec(&self, bin: &str) -> bool

Does this agent explicitly hold bin?

bin may be a bare name (cargo) or the absolute path the kernel refused (/Users/d/.cargo/bin/cargo) — a denial always reports the latter, so both sides are compared by file name. An allowlist entry may itself be absolute, which is why the normalisation is symmetric.

Deliberately CONSERVATIVE: under Allowlist mode the sandbox also re-allows the system exec paths (/usr/bin, /bin, …), so an agent can in fact run /usr/bin/git without naming it. Resolving that would mean replicating the runtime’s PATH augmentation and Seatbelt’s system-path exemption down here, and it would answer the wrong question anyway: a binary that resolves to a system path is one nobody needed to delegate. Under-reporting routes work to an agent that provably holds the binary; over-reporting would route it to one that dies with the same EPERM.

Source

pub fn can_write(&self, path: &Path) -> bool

Can it write anywhere at or under path?

Source

pub fn privilege_breadth(&self) -> u32

How much privilege this agent carries, for least-privilege dispatch (P4): among the agents that CAN do the job, prefer the one carrying the least unrelated power. Without this the ranking silently prefers the most capable agent — which is the one that undoes every containment decision made elsewhere.

A heuristic, and openly so: writable roots dominate (they are what an escaped task can damage), then egress (what it can exfiltrate to), then breadth of exec.

Trait Implementations§

Source§

impl Clone for AgentFacts

Source§

fn clone(&self) -> AgentFacts

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AgentFacts

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more