v3/docs/adr/ADR-336-agent-authorization-propagation.md
Status: Proposed Authors: claude (dream-cycle agent, 2026-05-31) Related: ADR-012 (MCP Security Features), ADR-013 (Core Security Module), ADR-131 (ToolOutputGuardrail), #[tonight's issue]
Three Grade A papers published May 2026 identify a security layer Ruflo currently lacks — authorization propagation across agent delegation chains — that is architecturally distinct from the content-screening gap addressed by ADR-131.
ADR-131 covers WHAT agents receive (tool output content screening for injected instructions).
This ADR covers WHO agents can act as and what they are authorized to delegate.
arXiv:2605.22333 (Grade A, empirical): 40.55% of 7,973 live MCP servers expose tools with zero authentication; 96.6% of OAuth-enabled servers contain ≥1 exploitable flaw. Ruflo registers MCP tools but performs no runtime authentication check on server identity before accepting tool responses.
arXiv:2605.28914 — AIRGuard (Grade A, controlled benchmark): Runtime authority control at the action execution layer reduces agent attack success from 36.3% to 5.5% (−85%). The key primitive is least-privilege authorization checked per-action, not per-session.
arXiv:2605.05440 — Authorization Propagation (Grade A, formal analysis): Multi-agent delegation creates an "authorization propagation" problem with seven structural requirements not solvable by RBAC, ABAC, or ReBAC alone. When an agent delegates a task via SendMessage, the receiving agent may escalate the granted scope by calling tools or sub-agents the original caller was not authorized to invoke.
arXiv:2605.26497 — Dual-Graph Provenance Defense (Grade A): Comparing an execution provenance graph against an authorization intent graph reduces indirect prompt injection success from 40% to 1%.
@claude-flow/security provides:
InputValidator — boundary input validation (Zod-based)PathValidator — path traversal preventionSafeExecutor — command injection protectionPasswordHasher, TokenGenerator — credential utilitiesNone of these track authorization scope across agent delegation boundaries, verify MCP server identity, enforce per-action privilege, or produce an execution provenance record.
Add AgentAuthorizationPropagator as a new component in @claude-flow/security.
File: v3/@claude-flow/security/src/authorization/propagator.ts
interface AuthScope {
principalId: string; // originating agent identity
grantedTools: string[]; // MCP tool IDs this scope allows
delegationDepth: number; // max remaining delegation hops
expiresAt: number; // unix ms
}
interface SendMessageEnvelope {
scope: AuthScope; // NEW — attached to every SendMessage
payload: unknown;
}
class AgentAuthorizationPropagator {
// Attach reduced scope to outbound SendMessage
wrapOutbound(msg: unknown, currentScope: AuthScope, requestedTools: string[]): SendMessageEnvelope;
// Validate inbound tool call against current delegation scope
checkToolCall(toolId: string, scope: AuthScope): { allowed: boolean; reason?: string };
// Verify MCP server presented valid auth before accepting its response
verifyServerAuth(serverId: string, credential: unknown): boolean;
// Record action in provenance log for dual-graph audit
recordAction(agentId: string, toolId: string, scope: AuthScope, outcome: 'allowed' | 'denied'): void;
}
File: v3/@claude-flow/cli/src/mcp/auth-validator.ts
Before any tool response from an MCP server enters agent reasoning:
UNAUTHENTICATED_MCP_SERVER errorv3/@claude-flow/hooks/src/pre-task.ts — initialize scope on task creationv3/@claude-flow/cli/src/mcp/ — add auth-validator.ts, call before tool result processing@claude-flow/security public API — export AgentAuthorizationPropagatorscope on SendMessage envelope is optional in v1. Agents without scope set operate in a permissive legacy mode (all tools allowed, depth unlimited). A CLAUDE_FLOW_STRICT_AUTH=true env var enables enforcement mode.SafeExecutor is unchanged.Positive
Negative / Trade-offs
scope field adds ~100 bytes to every SendMessage envelope (negligible vs payload)Deferred