Security boundaries
Identity, capabilities, tool approval and custody are separate contracts.
Forge supplies primitives that an application composes into an execution policy. Optional identity fields and automatic approval defaults exist in several implementations; applications requiring accountable actions must configure stricter boundaries explicitly.
Before execution
- Validate the signed principal and its lineage where required.
- Verify authority and narrow scopes for delegated operations.
- Validate tool arguments and apply an explicit approval policy.
- Keep production keys and provider credentials out of browser bundles, logs and examples.
- Treat model output, fetched pages and remote MCP metadata as untrusted data.
During and after execution
Set bounded iteration, token and time budgets. Preserve cancellation and unknown outcomes. Correlate tool calls and results, and check actual remote receipts before claiming settlement or durable completion. Restrict telemetry contents and protect persisted signing material.
The identity, capability, tool and telemetry references identify concrete source boundaries. A documentation publication is not a security certification of deployed agents.