Frontmatter
| id | 7959 |
| title | Epic: Agent Security & Capabilities |
| state | Closed |
| labels | epicstaleaiarchitecture |
| assignees | [] |
| createdAt | Nov 30, 2025, 10:52 PM |
| updatedAt | Mar 15, 2026, 5:08 AM |
| githubUrl | https://github.com/neomjs/neo/issues/7959 |
| author | tobiu |
| commentsCount | 2 |
| parentIssue | null |
| subIssues | [] |
| subIssuesCompleted | 0 |
| subIssuesTotal | 0 |
| blockedBy | [] |
| blocking | [] |
| closedAt | Mar 15, 2026, 5:08 AM |
Define and implement the security model for Agent-initiated browser actions.
Scope:
component:read,component:write,code:load).Neo.ai.server.WebSocketto validate RPC calls against the Agent's capability token.eval) in the browser context unless explicitly authorized.Reference:
.github/AGENT_ARCHITECTURE.md