2026-10-11 18:03 UTC

Verb Authority’s maintainer claims the released library can enforce authority checks on individual AI tool-call arguments, enabling finer-grained least-privilege controls than tool-level permissions alone.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security agent-authorization tool-call-securityyairsabagVerb Authority

What is this?

Verb Authority is presented as a released library by maintainer yairsabag that intercepts AI tool calls and applies authorization checks to individual arguments, rather than granting permission to an entire tool. The intended security model is finer-grained least privilege enforced before execution, consistent with supplied snippets advocating operation-level governance and warning that tool availability alone may not be an adequately enforced boundary. However, none of the supplied search snippets directly documents Verb Authority’s implementation, release, or maintainer, so those specifics remain supported only by the case titles and claim.

Why it matters to Scott

Scott already specifies deterministic, pre-execution authority checks over bounded agent actions in Decision Authority Infrastructure and Capability Tokens, while the radar already tracks substantially similar tool-call authorization layers in Conduct and AC2. Per-argument enforcement is a concrete implementation of that position, but the supplied material does not establish enough novelty, adoption, or technical validation to make it more than another example of an already-held and actively tracked pattern.
ip:framework.decision-authority-infrastructureip:concept.capability-tokensdev:concept.deterministic-agent-control-planeradar:conduct-tool-call-guardrailsradar:ac2-agent-security-protocolradar:concept.agent-securityradar:concept.tool-calling
queries asked of Scott's wikis
  • argument-level authorization for agent tool calls
  • least-privilege boundaries in agent harnesses
  • pre-execution policy enforcement for tool use
  • capability security and scoped agent permissions
  • MCP authorization beyond tool-level access
  • runtime interception and validation of agent actions

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Verb Authority – per-argument authority checks for AI tool callsyairsabag10
🟧 echo.github ⭐An implementation of per-argument authority checks for AI tool calls.yairsabag——

Interpretation history

Decision trace