Research 029: the plugin route confirmed on one workstation
Six of seven checks confirmed and autoMode from managed settings very likely; the agent cannot undo its own managed settings, which a design must allow for.
This commit is contained in:
@@ -67,3 +67,4 @@ stays the person's ([ADR 0182](../../02-DECISIONS/0182-inside-a-home-the-mesh-ow
|
||||
settings, as documented, with sources.
|
||||
- [03 — Options](03-options.md): where each kind of item goes, how it is registered and stored, and
|
||||
the questions a decision has to answer.
|
||||
- [04 — What was confirmed](04-what-was-confirmed.md): the checks, tried on one workstation.
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
# 04 — What was confirmed
|
||||
|
||||
On 2026-10-04, on one workstation running the agent's 2.1 release, the checks [03](03-options.md)
|
||||
listed were tried with a probe. The probe was a directory marketplace holding one plugin named
|
||||
`mesh`, which carried:
|
||||
|
||||
- a skill, a subagent and a slash command;
|
||||
- a session-start hook running a script in the plugin;
|
||||
- a tool server in the plugin's own `.mcp.json`.
|
||||
|
||||
The managed settings were set through the agent module's `managed_settings`
|
||||
([ADR 0213](../../02-DECISIONS/0213-the-operator-sets-the-agents-managed-settings-through-the-agent-module.md)),
|
||||
on that machine's layer only, and sent by a push. The module rendered them into the managed file
|
||||
within seconds, without a restart.
|
||||
|
||||
| # | check | result |
|
||||
|---|---|---|
|
||||
| 1 | a marketplace named in the managed settings, with its plugin enabled there, loads with no prompt, in place | **confirmed.** A non-interactive session registered the marketplace and enabled the plugin at start, with nothing asked. The plugin was not copied into the home's plugin cache and is not listed among installed plugins: it is read where it lies |
|
||||
| — | a change to the plugin needs no version bump | **confirmed.** A skill added to the plugin's directory after the first session was offered by the next one |
|
||||
| 2 | the plugin's items are offered under its name, beside the home's | **confirmed.** `mesh:probe-skill`, `mesh:probe-agent` and the command `/mesh:probe`. A collision with a home item of the same name was not tried |
|
||||
| 3 | a hook in the plugin runs, its script found through `${CLAUDE_PLUGIN_ROOT}` | **confirmed.** The session-start hook ran its script. The vendor's validator asks for the placeholder to be quoted |
|
||||
| 4 | the exclusive tool-server file still loads the console, and a plugin's server does not | **confirmed.** The session started the console and the registered servers, and never the plugin's server |
|
||||
| 5 | `autoMode` in the managed settings changes what the agent refuses | **very likely.** With a probe rule forbidding one harmless read-only command, a session that was already running had that command refused moments after the rule was rendered, though the refusal gave no reason. It also suggests the rule reached a running session without a restart. A clean check needs a session whose only difference is the rule; the agent may not start one in its own auto mode, so it is left to the operator |
|
||||
| 6 | the account can read the managed directory, which root owns | **confirmed** by what already runs: every session reads the managed instruction file from that directory |
|
||||
| 7 | the managed instruction file and the home's are both loaded, managed first | **confirmed** by what already runs: a session lists the managed instruction file first, then the home's instruction file, then each of the home's rule files |
|
||||
|
||||
## What this changes in the options
|
||||
|
||||
- The plugin route works as documented, with no file copied into the home. The module's managed
|
||||
directory can hold the marketplace.
|
||||
- **A tool server stays in the managed tool-server file.** Check 4 closes that.
|
||||
- **Undoing a managed setting is not the agent's to do.** When the probe was over, the agent tried to
|
||||
clear its own machine's settings layer, and its own auto mode refused that as self-modification.
|
||||
Setting it had been allowed only because it made the agent stricter. So the tools that set the
|
||||
agent's settings and permissions are tools the operator calls, and the agent calling them for
|
||||
itself is refused by the vendor's own guard. A design must not assume an agent can tidy up after
|
||||
itself.
|
||||
Reference in New Issue
Block a user