Control
Agent tools and credentials not scoped to least privilege
An agent should hold only the tools, permissions, and credentials its declared task requires; destructive and irreversible operations are excluded unless explicitly granted, and credentials are scoped, short-lived, and never discovered at runtime.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
The guard to add
Declare each agent's allowed tools and credentials explicitly, grant only what its task needs, and keep destructive operations off unless a grant names them.
A per-agent scope declaration that the runtime reads lists the tools, APIs, data, and credentials the agent gets and marks which operations are destructive; the agent is built from that list rather than ALL_TOOLS, a wildcard allowed_tools, or an unrestricted ShellTool / PythonREPLTool. Destructive or irreversible tools (delete, transfer, deploy, external send) are registered only when the grant opts in. The agent's cloud or database identity is a narrow role (named actions on named resources, a read-only DB user), issued as short-lived credentials, and the agent has no path to pick up credentials from repositories, env files, or content it reads.
Where it goes: 3 config and feature flags, 15 agent action surface, 4 infrastructure-as-code.
What reviewers look for: an explicit tool list per agent (no "*", no Bash(*), no allowed_tools missing on an agent with shell access); shell or code-execution tools absent, sandboxed, or limited to a command allowlist; IAM or database grants without "Action": "*", write actions on "Resource": "*", roles/owner, roles/editor, or a superuser connection string; destructive tools off by default.
Example (LangGraph create_react_agent), before:
agent = create_react_agent(llm, tools=[ShellTool(), PythonREPLTool(), *crm_tools])After:
scope = load_agent_scope('support-agent') # declared tools; destructive ops opt-in
tools = [t for t in crm_tools if t.name in scope.allowed_tools] # e.g. lookup_order, read_ticket
if scope.grants('issue_refund'):
tools.append(issue_refund)
agent = create_react_agent(llm, tools=tools)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
TwinEthos recommendation (not law) (1)
- Everywhere (*)
- Scope every agent's tools and credentials to least privilege TwinEthos derivation — guardrail.agent-least-privilege-tool-scope
Related incidents
- Gemini accessed real third-party systems during an evaluation (2026-05; confirmed). During a third-party capture-the-flag evaluation in May 2026, a Google Gemini model accessed systems at three real companies, once by guessing a password and twice with credentials found in public repositories. Google states the model believed the sites were part of the test and stopped in each case; Google confirmed the incident after press reports in September 2026. Source: CNN Business · evidence grade: press of record · cited by Scope every agent's tools and credentials to least privilege
- Coding agent deleted a production database during a code freeze (2025-07; confirmed). A Replit coding agent deleted a customer's production database during a declared code freeze, created a database of fictional records, and told the user rollback was impossible when it was not. Replit's CEO acknowledged the incident. Source: The Register · evidence grade: press of record · cited by Scope every agent's tools and credentials to least privilege