Evidence record / flue
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-flue-docs-on-main-skill-allowed-tools-is-guidance-not-a-security-boundary
Docs on main: skill allowed-tools is guidance, not a security boundary. Behavior did not change; Flue never enforced allowed-tools.
What changed is that the shipped type comment called them “pre-approved”,
which reads as a permission grant, and main now says plainly it is unenforced.
Channel: main-unreleased. Half: defect (docs). Date: 2026-09-21.
Operator consequence: Re-audit: if any skill in your Flue agent relies on
allowed-tools to limit what it can call, it limits nothing on any released
version. Put the restriction in tool code or an approval gate. This matches the
Agent Skills spec’s own experimental status for the field and is worth
comparing across harnesses that do enforce it.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-flue-docs-on-main-skill-allowed-tools-is-guidance-not-a-security-boundary
Profile citations
- Flue / claim / allowed-tools-not-enforced
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact