Agent, Tool Calling & Security Architecture
Agent→tool selection→schema→args validation→Backend API architecture and AI is not superuser
Khóa tool authentication, permission boundaries, pending-only writes, HITL, audit và red-team.
Đọc và bookmark được phép; mọi mutation vẫn bị khóa server-side cho đến khi week trước PASS.
PASS ≥ 80%
learner artifacts
Agent→tool selection→schema→args validation→Backend API architecture and AI is not superuser
Read tool such as get_low_stock_products, argument schema/limits, authorization, row limit and audit
create_purchase_request tool, source=AI, DRAFT/PENDING, no approve tool, Manager approval and workflow continuation
Agent service auth, user actor context, Backend RBAC, tool permission, expired token and 401/403 tests
Agent audit actor/tool/sanitized args/result/timestamp/correlation/latency, rate/row/quantity limits, timeout/malformed output and retry safety
Ignore-rules, self-approve, secret extraction, SQL, huge quantity, malicious retrieved text, wrong role, expired token, timeout and malformed output red-team
Two controlled tools, E2E Agent workflow, DRAFT/PENDING/Manager approval, AI audit, red-team report and final config inventory prep