ForgeLayer

Task Capability Packages · Part 125

Bound future agent authority to one task, one workspace, and one repository.

ForgeLayer computes a temporary internal package by intersecting platform, workspace, repository, task, policy, human approval, verification, expiry, revocation, and budget controls. The result can only remove authority.

Deterministic internal modelActive packages: 0Credentials issued: falseApproval authority evaluator-owned

Strict intersection

Every layer must agree; a lower boundary always wins.

No policy, user label, task request, or local action can expand a stricter upstream boundary.
  1. 01Platform hard boundaries
  2. 02Workspace authority
  3. 03Repository connection
  4. 04Base task request
  5. 05Executable policy
  6. 06Human approval
  7. 07Verification and evidence
  8. 08Time and cost budget
  9. 09Expiry and revocation
  10. 10Effective preview package

Controlled Task authority

Task Capability Packages and Cost & Resource Budgets

Allowed paths and tools describe the maximum future preview scope. Platform controls still deny repository access and execution.
PreviewGlobally Disabled
capability-package-secure-payment-webhook-v1

Secure Payment Webhook

ForgeLayer intersected platform, workspace, repository, task, policy, approval, verification, expiry, revocation, and budget controls. The result cannot expand platform authority.

Workspace
ForgeLayer Guided Beta
Controlled Task
controlled-task-secure-payment-webhook
Repository
acme-payments/payment-webhook-service
Branch
demo/secure-payment-webhook
Policy snapshot
policy-snapshot-5cc8bbf1
Package version
task-capability-package-v1
Expiry
Not Expired
Revocation
Not Revoked

Allowed preview scope

exact:app/api/payments/webhook.ts
exact:tests/payment-webhook.test.ts

Blocked scope

directory:lib/auth
directory:config
glob:**/.env*
glob:**/secrets/**

Tools and commands

Preview tools: Read-only PR diff inspection, RepoBrain policy preview

Blocked tools: secret reader, repository writer, shell executor

Preview categories: test, lint, typecheck, inspect

Prohibited: migration, deploy, package_install, destructive, arbitrary_shell

Network and secrets

Network: Disabled

Secrets: None

Tree knowledge: Incomplete Not Fetched

Execution / dispatch: disabled / disabled

Effective budget

$2.00 USD maximum estimate

14,000 tokens maximum

40 minutes · 2 correction loops

Metered / billed: false / false

Evidence

  • missingsecurity_review_evidence
  • missingrollback_plan

Verification

  • missingpayment_webhook_security
  • missingauth_session_boundary

Approval policy definitions

Current evaluator status: Satisfied

  • policy definitionowner

Why authority is denied

  • read metadata is globally disabled.
  • Trusted server identity is not enabled.
  • Production authentication and persistence are disabled.
  • Active trusted workspace membership is required.
  • A validated workspace-owned repository connection is required.
  • Evidence required: security_review_evidence.
  • Evidence required: rollback_plan.
  • Verification required: payment_webhook_security.
  • Verification required: auth_session_boundary.
  • Repository access, agent dispatch, execution, network, secrets, GitHub writes, pull requests, workflows, and automatic merge are globally disabled.
  • The package is an internal preview and no active authority was issued.

Current next: Approval requirement satisfied. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

PreviewGlobally Disabled
capability-package-harden-risky-prompt-v1

Harden Risky Prompt

ForgeLayer intersected platform, workspace, repository, task, policy, approval, verification, expiry, revocation, and budget controls. The result cannot expand platform authority.

Workspace
ForgeLayer Guided Beta
Controlled Task
controlled-task-harden-risky-prompt
Repository
acme-ai-support/refund-assistant-prompts
Branch
demo/harden-risky-prompt
Policy snapshot
policy-snapshot-d8a299d8
Package version
task-capability-package-v1
Expiry
Not Expired
Revocation
Not Revoked

Allowed preview scope

directory:lib/prompts
directory:prompts

Blocked scope

directory:app
directory:lib/auth
glob:**/.env*
glob:**/secrets/**

Tools and commands

Preview tools: PromptForge deterministic analyzer, Read-only policy preview

Blocked tools: external prompt runner, secret reader, repository writer

Preview categories: inspect

Prohibited: migration, deploy, package_install, destructive, arbitrary_shell

Network and secrets

Network: Disabled

Secrets: None

Tree knowledge: Incomplete Not Fetched

Execution / dispatch: disabled / disabled

Effective budget

$1.25 USD maximum estimate

7,000 tokens maximum

20 minutes · 2 correction loops

Metered / billed: false / false

Evidence

  • missingpromptforge_analysis

Verification

  • missingprompt_injection_security_tests

Approval policy definitions

Current evaluator status: Approval Revoked

  • policy definitionreviewer

Why authority is denied

  • read metadata is globally disabled.
  • Trusted server identity is not enabled.
  • Production authentication and persistence are disabled.
  • Active trusted workspace membership is required.
  • A validated workspace-owned repository connection is required.
  • Evidence required: promptforge_analysis.
  • Verification required: prompt_injection_security_tests.
  • Repository access, agent dispatch, execution, network, secrets, GitHub writes, pull requests, workflows, and automatic merge are globally disabled.
  • The package is an internal preview and no active authority was issued.

Current next: Keep current authorization revoked. Current authorization is revoked. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

PreviewGlobally Disabled
capability-package-investigate-failing-tests-v1

Investigate Failing Tests

ForgeLayer intersected platform, workspace, repository, task, policy, approval, verification, expiry, revocation, and budget controls. The result cannot expand platform authority.

Workspace
ForgeLayer Guided Beta
Controlled Task
controlled-task-investigate-failing-tests
Repository
acme-checkout/checkout-ui
Branch
demo/investigate-failing-tests
Policy snapshot
policy-snapshot-69ecde00
Package version
task-capability-package-v1
Expiry
Not Expired
Revocation
Not Revoked

Allowed preview scope

directory:tests
exact:app/checkout/confirmation.tsx
exact:package.json

Blocked scope

directory:.github/workflows
directory:production
glob:**/.env*
glob:**/secrets/**

Tools and commands

Preview tools: Read-only test evidence inspection, AgentOS routing preview

Blocked tools: workflow dispatcher, shell executor, repository writer

Preview categories: test, lint, typecheck, inspect

Prohibited: migration, deploy, package_install, destructive, arbitrary_shell

Network and secrets

Network: Disabled

Secrets: None

Tree knowledge: Incomplete Not Fetched

Execution / dispatch: disabled / disabled

Effective budget

$1.50 USD maximum estimate

10,000 tokens maximum

30 minutes · 2 correction loops

Metered / billed: false / false

Evidence

  • missingfailing_test_output
  • missingpassing_rerun_output

Verification

  • missingtest_failure_reproduced
  • missingtest_remediation_verified

Approval policy definitions

Current evaluator status: Satisfied

  • policy definitionreviewer

Why authority is denied

  • read metadata is globally disabled.
  • Trusted server identity is not enabled.
  • Production authentication and persistence are disabled.
  • Active trusted workspace membership is required.
  • A validated workspace-owned repository connection is required.
  • Evidence required: failing_test_output.
  • Evidence required: passing_rerun_output.
  • Verification required: test_failure_reproduced.
  • Verification required: test_remediation_verified.
  • Repository access, agent dispatch, execution, network, secrets, GitHub writes, pull requests, workflows, and automatic merge are globally disabled.
  • The package is an internal preview and no active authority was issued.

Current next: Keep workflow progression blocked by the active kill switch. An active kill switch blocks workflow progression. Repository verification has not run. Execution transport is disabled. Dispatch remains disabled.

Platform prohibitions

The package cannot override ForgeLayer’s disabled capabilities.

DisabledAuthentication

authentication is globally disabled in the current private beta.

DisabledPersistence

persistence is globally disabled in the current private beta.

DisabledRepository Connection

repository connection is globally disabled in the current private beta.

DisabledRepository Metadata Access

repository metadata access is globally disabled in the current private beta.

DisabledRepository Content Access

repository content access is globally disabled in the current private beta.

DisabledRepository Write

repository write is globally disabled in the current private beta.

DisabledBranch Creation

branch creation is globally disabled in the current private beta.

DisabledCommit Creation

commit creation is globally disabled in the current private beta.

DisabledPull Request Creation

pull request creation is globally disabled in the current private beta.

DisabledGithub Posting

github posting is globally disabled in the current private beta.

DisabledWorkflow Dispatch

workflow dispatch is globally disabled in the current private beta.

DisabledAgent Dispatch

agent dispatch is globally disabled in the current private beta.

DisabledExternal Agent Call

external agent call is globally disabled in the current private beta.

DisabledCommand Execution

command execution is globally disabled in the current private beta.

DisabledNetwork Access

network access is globally disabled in the current private beta.

DisabledAutomatic Merge

automatic merge is globally disabled in the current private beta.

DisabledBilling

billing is globally disabled in the current private beta.

DisabledProduction Telemetry

production telemetry is globally disabled in the current private beta.

DisabledRead Metadata

read metadata is globally disabled in Part 125.

DisabledRead Tree

read tree is globally disabled in Part 125.

DisabledRead Content

read content is globally disabled in Part 125.

DisabledWrite Repository

write repository is globally disabled in Part 125.

DisabledCreate Branch

create branch is globally disabled in Part 125.

DisabledCreate Commit

create commit is globally disabled in Part 125.

DisabledCreate Pull Request

create pull request is globally disabled in Part 125.

DisabledGithub Posting

github posting is globally disabled in Part 125.

DisabledWorkflow Dispatch

workflow dispatch is globally disabled in Part 125.

DisabledAgent Dispatch

agent dispatch is globally disabled in Part 125.

DisabledExecution

execution is globally disabled in Part 125.

DisabledNetwork Access

network access is globally disabled in Part 125.

DisabledSecret Access

secret access is globally disabled in Part 125.

DisabledAuto Merge

auto merge is globally disabled in Part 125.