← Lab L10 — State Checkpoints & Recovery All modules Lab L12 — Trajectory Tracing & Decision Lineage →

Lab L11 — Capability Gate & Agent Security Kernel (Pure Go)

Phase 8 · SECURITY & GOVERNANCE — Lab L11
Status: Authored & Empirically Verified.
Student Lab Package: Authenticated Direct Download from VTAlgo Platform (hefesto-lab11-capability-gate.zip)
Branches: main (starter template) · solution (reference architecture).
Canonical Path: Student repo only (hefesto-lab11-capability-gate) — not E:\bridle, not the live product.

1. Laboratory Objective

Construct from scratch in pure Go standard library an enterprise-grade Agent Security Kernel & Capability Gate, proving empirically that autonomous multi-agent workflows can be fortified against privilege escalation, unauthorized network egress, memory poisoning, and indirect prompt injections with zero runtime performance degradation.

The student implements:


2. The Five Cardinal Security Subsystems

┌──────────────────────────────────────────────────────────────────────────┐
│             HEFESTO AGENT SECURITY KERNEL ARCHITECTURE (PURE GO)         │
│                                                                          │
│  ┌─────────────────────────┐           ┌──────────────────────────────┐  │
│  │ 1. Capability Gate      │           │ 2. Process Sandbox           │  │
│  │    uint64 Bitmask O(1)  ├──────────►│    SafePath Anti-Traversal   │  │
│  │    Delegation Ceilings  │           │    Zero-Trust Network Egress │  │
│  └───────────┬─────────────┘           └──────────────┬───────────────┘  │
│              │                                        │                  │
│              ▼                                        ▼                  │
│  ┌─────────────────────────┐           ┌──────────────────────────────┐  │
│  │ 3. Memory Enclave       │           │ 4. Injection Oracles         │  │
│  │    Persisted ≠ Trusted  ├──────────►│    HMAC Canary Engine        │  │
│  │    Contradiction Traps  │           │    Go AST Import Whitelist   │  │
│  └───────────┬─────────────┘           └──────────────┬───────────────┘  │
│              │                                        │                  │
│              ▼                                        ▼                  │
│  ┌────────────────────────────────────────────────────────────────────┐  │
│  │ 5. Governance Receipts & 14/14 Tests in <350ms (Zero Dependencies) │  │
│  └────────────────────────────────────────────────────────────────────┘  │
└──────────────────────────────────────────────────────────────────────────┘

1. Capability Gate (pkg/capability)

2. Execution Sandbox (pkg/sandbox)

3. Memory Enclave (pkg/memory)

4. Injection & AST Oracles (pkg/injection)

5. Security Kernel & Receipts (pkg/governance)


3. Quick Start & Test Execution

# Extract student lab package
cd hefesto-lab11-capability-gate

# Run full test suite with race detector (14/14 passing in <350ms)
go test -v -race ./...

# Build the security CLI
go build -o bin/security-cli.exe ./cmd/security-cli

# Mode 1: Nominal execution (Authorized implementer and auditor tasks)
./bin/security-cli.exe -mode nominal

# Mode 2: Privilege escalation simulation (Subordinate attempts CapAdmin)
./bin/security-cli.exe -mode escalation

# Mode 3: Multi-vector adversarial attack simulation (Injection, leaks, traversal)
./bin/security-cli.exe -mode attack-simulation

4. Benchmark & Telemetry Results

Executing the complete benchmark suite on standard developer hardware confirms sub-microsecond authorization latencies:

=== RUN   TestConcurrencyAndBenchmarks
    gate_test.go:48: Executed 1000 concurrent capability checks in 522.4µs (522.4ns/op)
--- PASS: TestConcurrencyAndBenchmarks (0.00s)
PASS
ok      github.com/vtalgo/hefesto-lab11-capability-gate/pkg/capability      0.034s
ok      github.com/vtalgo/hefesto-lab11-capability-gate/pkg/sandbox         0.028s
ok      github.com/vtalgo/hefesto-lab11-capability-gate/pkg/memory          0.031s
ok      github.com/vtalgo/hefesto-lab11-capability-gate/pkg/injection       0.038s
ok      github.com/vtalgo/hefesto-lab11-capability-gate/pkg/governance      0.032s
ok      github.com/vtalgo/hefesto-lab11-capability-gate/tests               0.304s

All 14 tests pass cleanly with zero allocations in the hot path, establishing that rigorous bank-grade security governance imposes negligible overhead on agent execution speed.