Pimp My IDE / garage dispatch
Back to garage
October 5, 2026 | agents / authorization / task scope

Give the agent a key cut for one job.

A short-lived token is not least privilege by itself. Cut authority to the exact resource and action. Bind it to the caller. Reject anything wider at the tool boundary.

Identity names the driver. A task grant limits the trip.

The prompt is not an authorization rule.

Zenity Labs reported an Agentforce attack that began with instructions hidden in a public lead record. When an employee later asked the agent to review leads, the injected text directed the same subagent to query account data and place values in an external hostname. Zenity says Salesforce fixed the reported URL-redaction bypass.[1]

The important boundary sat earlier in the route. The subagent could read both leads and accounts. The injected instruction did not need a new privilege. It used authority the agent already had. A better output filter can close that specific exit. It does not narrow the records available to the task.

Do not ask the model to remember the fence. Put the fence where the tool executes.

Short-lived and task-scoped answer different questions.

A token can expire in one minute and still allow too much during that minute. GitHub's current App installation tokens keep repository scope, permissions, and a one-hour expiry while changing to a longer stateless format. GitHub tells integrators to treat tokens as opaque strings and update storage, gateways, and redaction rules that assume the old length.[2] That is a transport and validation migration. It is not a claim that the token now carries narrower task intent.

OAuth Rich Authorization Requests shows what finer authorization can look like. Its authorization_details parameter can describe actions, locations, amounts, and named recipients instead of relying on one coarse scope string.[3] The agent version of that idea needs the resource server or tool to enforce the details on every call.

The valet-key proposal is real, but the standard is not finished.

Tenuo proposes signed warrants that name capabilities, arguments, a holder, and an expiry. A holder can pass an equal or narrower grant to another agent. The receiving tool verifies the chain and rejects a call outside the grant. The project publishes an Apache-2.0 implementation for Python and TypeScript.[4]

We installed the released Python package at version 0.3.2 and ran a local smoke check. A warrant for query_records on Lead/LEAD-42 allowed that exact request. The same warrant denied Account/* with ConstraintViolation. This proves the narrow example, not production key custody, revocation, framework integration, policy completeness, or resistance to every bypass.

The related Attenuating Authorization Tokens document is an individual Internet-Draft. The IETF page says it is not endorsed by the IETF and has no formal standing in the standards process.[5] Treat it as a design proposal under review, not a finished standard.

Cut the smallest useful key.

CISA and international partners advise teams to avoid broad or unrestricted agent access, especially around sensitive data and critical systems.[6] Turn that advice into five fields the enforcement point can read: task, resource, action, holder, and expiry.

Start with one common task. Resolve vague language such as "latest lead" to a stable record before minting the grant. Permit one action on that record. Bind the grant to the expected caller. Keep the life short enough for the task. Log the allow or denial without logging the secret itself.

Interactive makeover / valet-key cutter

Cut a task grant before the agent drives.

Traditional purpose replaced: one broad role toggle. Better version: native controls cut four independent restrictions into a visible key and produce a copyable policy template. This page does not mint a credential or call a tool.

Describe one task

Use identifiers that the tool can compare without asking a model to interpret them.

Cuts to require
60 seconds
5 seconds120 seconds
0 of 4 cuts selectedPolicy template only
Task key / enforcement cuts

Agent valet key

Allowed targetNot constrained
Expiry60 seconds
EvidenceNot run

No enforcement cut is selected.

Next cut: exact resource.

All four cuts means the policy template has the required sections. It does not prove that a credential was minted, a key was protected, a tool verified the grant, or the negative test ran.

Resource / action / holder / denial

Four cuts the tool can check.

01 / RESOURCE

Resolve before grant

Turn "latest lead" into one stable identifier before authority reaches the agent.

02 / ACTION

Permit one verb

Read is not harmless, and read access does not imply export, update, delete, or list.

03 / HOLDER

Bind the caller

A copied grant should fail when the caller cannot prove it holds the matching key.

04 / DENIAL

Test the fence

Send one forbidden request and keep the denial type beside the expected allow result.

Sources read

Source log and evidence boundary
  1. Zenity Labs, "SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce", published September 24 and read October 5, 2026. It documents the reported lead-record entry, the General CRM subagent permissions, the account-data query, the URL-redaction bypass, DNS exfiltration, disclosure timeline, and Salesforce remediation. The architectural lesson here is ours.
  2. GitHub Changelog, "Stateless GitHub App installation tokens rolled out", published October 2 and read October 5, 2026. It documents the new token format and length, unchanged repository scope, permissions, one-hour expiry, temporary-header retirement, and migration checks.
  3. RFC 9396, "OAuth 2.0 Rich Authorization Requests", published May 2023 and read October 5, 2026. It defines authorization_details for fine-grained authorization data and gives action, location, payment, and account examples. It is an adjacent standard, not the Tenuo format.
  4. Tenuo Engineering, "Give your agent a valet key", published October 2 and read October 5, 2026. It presents the task-scoped warrant model, implementation example, limits, integrations, and open-source repository. Tenuo is describing its own product.
  5. IETF Datatracker, "Attenuating Authorization Tokens for Agentic Delegation Chains", version 01 read October 5, 2026. The page labels it an active individual Internet-Draft and states that it is not endorsed by the IETF and has no formal standing.
  6. CISA, "CISA, US and International Partners Release Guide to Secure Adoption of Agentic AI", released May 1 and read October 5, 2026. It recommends avoiding broad or unrestricted access, starting with low-risk uses, and including agent security in the organization's risk model.
  7. Hacker News discussion item 49964877, resolved through the official HN API and read October 5, 2026. It pointed to the Tenuo article. At review time it had no comments, so it is a discovery route, not supporting evidence.

Artifact check: We cloned the public repository at revision 331854c66aaaefb71d8faa89ecabb63f396570a3. We installed the published tenuo==0.3.2 Python package in an isolated environment. One exact Lead/LEAD-42 request returned ALLOWED. One Account/* request returned DENIED:ConstraintViolation. We did not connect an agent framework, deploy a verifier, test key storage or revocation, reproduce SalesBleed, or audit the cryptography.