AG-025
Conflicting Destructive Tool Approval
medium
Page text and source link for your AI assistant. Nothing is sent automatically.
What Foo Guard detects
Global approval is enabled while a destructive tool explicitly disables its own approval requirement. Client precedence must be checked; an approval bypass has not been demonstrated.
When this rule triggers
The rule triggers when The same tool has destructive === true and requiresApproval === false, while humanApprovalRequired or destructiveOperationsRequireApproval is explicitly true.
Foo Guard evaluates the normalized configuration supplied to the scanner. A finding describes configuration risk; it does not establish that an attack occurred. An absent finding does not prove that an undeclared capability is safe.
How to fix
Align tool and global approval settings and test actual approval behavior at execution time.
Check the client’s precedence between global and per-tool approval. Align contradictory declarations and verify that destructive execution waits for approval. Missing fields, a non-destructive tool, or a tool requiring approval do not trigger this rule. This is a configuration conflict, not proof of a bypass.
Verify the change
Update the actual agent configuration and the underlying permissions or controls, then run the scanner again. Inspect the finding’s evidence path to confirm the intended setting changed. Do not clear a finding by changing a declaration that no longer reflects the deployed agent.
Test the affected workflow in an isolated environment, including an operation that should be denied. Keep related findings in view: fixing this rule does not automatically resolve other identity, permission, tool, or audit risks.