TwinEthosRequest access

Control

Coding-agent instructions and automation, or agent-chosen packages, not under review and verification

Coding-agent instruction files and automation are under required human review, coding agents in CI cannot act on untrusted events with write access or merge their own changes, and packages an agent chooses are verified to exist on an approved registry before install.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: An AI agent's authority, reach, inputs, and components are not bounded and accountable · control id cond.ai-generated-code-without-provenance-review

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

The guard to add

Require code-owner review of coding-agent instruction files, keep CI coding agents off untrusted triggers and self-merge, and check agent-chosen packages against an approved registry.

Repository and CI controls. CODEOWNERS entries cover AGENTS.md, CLAUDE.md, .github/copilot-instructions.md, .cursor/rules/, and .mcp.json, with branch protection requiring code-owner review. Workflows that run a coding agent (claude-code-action, codex-action, run-gemini-cli) trigger on pull_request or trusted comments rather than pull_request_target, hold the minimum token permissions (no contents: write on untrusted events), and never run gh pr merge --auto or --admin on the agent's own change. Where an agent installs packages at run time, the name is checked against an allowlist or resolved only from an approved internal index before install, never interpolated straight from model output into pip or npm.

Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 1 application source code, 15 agent action surface.

What reviewers look for: a CODEOWNERS pattern matching each agent instruction file and required code-owner review; coding-agent workflows with no pull_request_target, no contents: write, and no auto-merge step; runtime installs that take package names from an allowlist or approved index, not from an f-string or list built from model output.

Example (GitHub CODEOWNERS), before:

/src/  @acme/backend

After:

/src/                             @acme/backend
/AGENTS.md                        @acme/platform-security
/CLAUDE.md                        @acme/platform-security
/.github/copilot-instructions.md  @acme/platform-security
/.cursor/rules/                   @acme/platform-security
/.mcp.json                        @acme/platform-security

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

TwinEthos recommendation (not law) (1)

Related incidents