Expand description
Effect-based permissions: analyse what a tool execution actually affected on disk and make post-execution security decisions.
This module provides the EffectAnalyzer which inspects file paths for
sensitivity patterns (.env, Cargo.toml, Dockerfile, CI config, etc.)
and produces an EffectReport with a classified BlastRadius.
The resulting PostDecision feeds into the security policy to escalate
guarded effects (e.g. roll back .env modifications).
Structs§
- Effect
Analyzer - Inspects file paths for sensitivity and categorises blast radius.
- Effect
Report - What a tool execution actually affected on disk.
Enums§
- Blast
Radius - How widespread a tool’s effect is.
- Post
Decision - Decision after analysing the effects of a completed tool execution.
Functions§
- extract_
paths - Extract file paths referenced by a completed tool result and its originating invocation.