Skip to content

feat: expand safety model with scope, side effects, confirmation (#87) - #132

Merged
cursor[bot] merged 2 commits into
mainfrom
cursor/safety-model-c2a5
Sep 18, 2026
Merged

cursor[bot] merged 2 commits into
mainfrom
cursor/safety-model-c2a5

Conversation

@askmy-stack

Copy link
Copy Markdown
Owner

Summary

Expands the safety model beyond a single risk enum (#87):

  • PermissionScope (resource…global, plus unknown)
  • side_effects list (open vocabulary; documented common tags)
  • requires_confirmation: bool | None (null = undeclared)
  • Diff codes: tool.scope_escalated / scope_changed, side_effect_added / removed, confirmation_removed (critical for true→false) / added
  • Capture accepts manifest fields or MCP annotations — never invents values
  • Probes: max_scope, forbidden_side_effects
  • Docs: docs/safety.md, change-codes catalog, SECURITY.md note

Type of change

  • Enhancement / feature
  • Documentation
  • Tests / CI

Test plan

  • ruff / mypy / pytest (escalation, confirmation removed, probe gates, manifest capture)
  • CI on this PR

Closes #87

Open in Web Open in Cursor 

Add PermissionScope, side_effects, and requires_confirmation on ToolContract
with backward-compatible defaults. Diff emits escalation / confirmation
codes; capture accepts annotations without inventing values; probes support
max_scope and forbidden_side_effects.

Co-authored-by: Abhinaysai Kamineni  <askmy-stack@users.noreply.github.com>
@askmy-stack
askmy-stack marked this pull request as ready for review September 18, 2026 18:22
Co-authored-by: Abhinaysai Kamineni  <askmy-stack@users.noreply.github.com>
@cursor
cursor Bot merged commit 10e45d9 into main Sep 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Expand safety model: scope, side effects, and confirmation diffs

2 participants