Repository navigation
hallpass: check the *user's* permissions before a Strands tool runs (one decorator) #4549
roee-hersh
started this conversation in
Show and tell
Replies: 2 comments
Hi, the pattern you're describing sounds like it fits as an intervention. It lets you proceed, deny, and perform other decisions for tool calls according to an overridable handler. |
0 replies
|
@liramon2 Thanks, I'll look into interventions. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi all! I built an open-source guard for Strands tools and wanted to share it here.
The problem: a Strands agent usually calls Jira, GitHub, Slack or AWS with one bot credential. So any user who can talk to the agent can get it to do things they aren't allowed to do. Prompt instructions don't help: the tool call still runs with the bot's permissions.
The fix: hallpass is a small self-hosted service that asks the target system itself, live, whether this user may do this action on this resource. It answers
allow,denyorunknown, and anything butallowblocks the tool.In Strands it's one extra decorator:
A few details that matter for security:
@guardedkeeps the original signature, so the tool schema has nouserfield. The user comes from your session (ContextVar, callable or string). I tested it: even if the model injects"user": "admin@..."into the tool input, the check still runs for the real user.deny,unknown, or hallpass being unreachable all mean the tool body never runs.hallpass supports 11 systems today (Jira, Confluence, GitHub, GitLab, Slack, Google Workspace, Microsoft 365, Salesforce, AWS, Kubernetes, Argo CD). It's a single Go binary or a Docker image, with no database, under Apache 2.0.
Full Strands example:
examples/agent/strands_tool.py· Docs: docs/agents.mdI'd love feedback from Strands users, especially whether there's a more idiomatic place to hook this in, like a hook or tool-execution callback, instead of a decorator.
All reactions