Lab L11 — Capability Gate & Agent Security Kernel (Pure Go)
Phase 8 · SECURITY & GOVERNANCE — Lab L11
Status: Authored & Empirically Verified.
Student Lab Package: Authenticated Direct Download from VTAlgo Platform (hefesto-lab11-capability-gate.zip)
Branches:main(starter template) ·solution(reference architecture).
Canonical Path: Student repo only (hefesto-lab11-capability-gate) — notE:\bridle, not the live product.
1. Laboratory Objective
Construct from scratch in pure Go standard library an enterprise-grade Agent Security Kernel & Capability Gate, proving empirically that autonomous multi-agent workflows can be fortified against privilege escalation, unauthorized network egress, memory poisoning, and indirect prompt injections with zero runtime performance degradation.
The student implements:
- An atomic bitmask capability gate (
pkg/capability) supporting discreteuint64capability flags, constant-time $O(1)$ CPU register authorization, HMAC-SHA256 tokens with configurable TTL, and non-transitive delegation escalation traps. - An execution sandbox (
pkg/sandbox) enforcing strict path containment (SafePath) against../directory traversals, process command allowlisting, and a zero-trust network egress filter blocking raw IP literals and unapproved domains. - A zero-trust memory enclave (
pkg/memory) enforcing the dual axioms that *Persisted $\neq$ Trusted* and *Retrieved $\neq$ Safe*, equipped with SHA-256 provenance hashes, pre-admission validation gates, active contradiction traps, and strict tenant isolation. - A deterministic anti-injection engine (
pkg/injection) incorporating an HMAC canary token generator, terminal ANSI control code sanitizers, override regex pattern filters, and a native Go standard librarygo/parserAST import oracle. - A unified security kernel (
pkg/governance) coordinating all defensive layers and emitting tamper-evident, non-repudiable HMAC-SHA256 governance receipts. - A command-line interface (
cmd/security-cli) providing nominal execution, privilege escalation simulation, and multi-vector attack simulation modes. - A 14/14 deterministic test suite passing under Go's race detector in $<350$ ms with zero external third-party dependencies in
go.mod.
2. The Five Cardinal Security Subsystems
┌──────────────────────────────────────────────────────────────────────────┐
│ HEFESTO AGENT SECURITY KERNEL ARCHITECTURE (PURE GO) │
│ │
│ ┌─────────────────────────┐ ┌──────────────────────────────┐ │
│ │ 1. Capability Gate │ │ 2. Process Sandbox │ │
│ │ uint64 Bitmask O(1) ├──────────►│ SafePath Anti-Traversal │ │
│ │ Delegation Ceilings │ │ Zero-Trust Network Egress │ │
│ └───────────┬─────────────┘ └──────────────┬───────────────┘ │
│ │ │ │
│ ▼ ▼ │
│ ┌─────────────────────────┐ ┌──────────────────────────────┐ │
│ │ 3. Memory Enclave │ │ 4. Injection Oracles │ │
│ │ Persisted ≠ Trusted ├──────────►│ HMAC Canary Engine │ │
│ │ Contradiction Traps │ │ Go AST Import Whitelist │ │
│ └───────────┬─────────────┘ └──────────────┬───────────────┘ │
│ │ │ │
│ ▼ ▼ │
│ ┌────────────────────────────────────────────────────────────────────┐ │
│ │ 5. Governance Receipts & 14/14 Tests in <350ms (Zero Dependencies) │ │
│ └────────────────────────────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────────────────────────────┘
1. Capability Gate (pkg/capability)
BitmaskFlags:CapReadDisk (1<<0),CapWriteIsolated (1<<1),CapCompileCode (1<<2),CapExecuteBinary (1<<3),CapNetworkEgress (1<<4),CapInspectAST (1<<5),CapReadMemory (1<<6),CapWriteMemory (1<<7),CapAdmin (1<<8).Authorize(token, required): Constant-time bitwise AND operation with TTL verification.Delegate(parent, childMask): Asserts(childMask & ^parent.Bitmask) == 0; aborts withErrPrivilegeEscalationif child requests permissions absent in the parent token.
2. Execution Sandbox (pkg/sandbox)
SafePath(relPath): Resolves target paths relative to a sandboxed root; rejects directory escapes,../traversal sequences, and unauthorized absolute paths withErrPathEscape.ValidateEgress(destination, port): Rejects direct IP literals (e.g.10.0.0.1) and non-TLS ports, ensuring network egress is restricted to whitelisted domains.
3. Memory Enclave (pkg/memory)
MemoryRecord: Captures discrete state fragments with SHA-256 provenance hashes binding tenant ID, author role, task ID, and timestamp.Admit(record): Pre-admission gate rejecting unverified provenance or candidates that contradict active authoritative invariants (ErrMemoryContradiction).Query(tenantID, key): Cryptographic tenant isolation rejecting cross-tenant inquiries withErrTenantMismatch.
4. Injection & AST Oracles (pkg/injection)
CanaryEngine: Seeds HMAC canary tokens (CANARY_SEC_<hash>) inside system prompts; tripsErrCanaryLeakedif model output or tools leak the token.PayloadSanitizer: Purges terminal ANSI escape sequences and blocks override keywords (ignore previous instructions).ASTOracle: Uses nativego/parserto inspect Go AST trees, rejecting unauthorized imports (e.g.net/httporos/exec) before compilation.
5. Security Kernel & Receipts (pkg/governance)
AuthorizeAndAudit: Orchestrates token validation, sandbox verification, and memory gating, emitting an immutableReceipt.VerifyReceipt: Constant-time validation usinghmac.Equal, guaranteeing mathematical non-repudiation for SOC 2 audits.
3. Quick Start & Test Execution
# Extract student lab package
cd hefesto-lab11-capability-gate
# Run full test suite with race detector (14/14 passing in <350ms)
go test -v -race ./...
# Build the security CLI
go build -o bin/security-cli.exe ./cmd/security-cli
# Mode 1: Nominal execution (Authorized implementer and auditor tasks)
./bin/security-cli.exe -mode nominal
# Mode 2: Privilege escalation simulation (Subordinate attempts CapAdmin)
./bin/security-cli.exe -mode escalation
# Mode 3: Multi-vector adversarial attack simulation (Injection, leaks, traversal)
./bin/security-cli.exe -mode attack-simulation
4. Benchmark & Telemetry Results
Executing the complete benchmark suite on standard developer hardware confirms sub-microsecond authorization latencies:
=== RUN TestConcurrencyAndBenchmarks
gate_test.go:48: Executed 1000 concurrent capability checks in 522.4µs (522.4ns/op)
--- PASS: TestConcurrencyAndBenchmarks (0.00s)
PASS
ok github.com/vtalgo/hefesto-lab11-capability-gate/pkg/capability 0.034s
ok github.com/vtalgo/hefesto-lab11-capability-gate/pkg/sandbox 0.028s
ok github.com/vtalgo/hefesto-lab11-capability-gate/pkg/memory 0.031s
ok github.com/vtalgo/hefesto-lab11-capability-gate/pkg/injection 0.038s
ok github.com/vtalgo/hefesto-lab11-capability-gate/pkg/governance 0.032s
ok github.com/vtalgo/hefesto-lab11-capability-gate/tests 0.304s
All 14 tests pass cleanly with zero allocations in the hot path, establishing that rigorous bank-grade security governance imposes negligible overhead on agent execution speed.