Skip to main content
A coding agent fixing a build needs to read error reports and follow useful clues. Some of that material may also contain instructions aimed at the agent itself. If the agent accepts a misleading instruction, asking that same agent to decide whether it was misled gives the instruction another chance to influence the answer. Silmaril’s principle of Independence calls for a security decision made separately from the agent’s reasoning.

Three separate responsibilities

The agent proposes an action. A defense evaluates the proposal against the trusted task and applicable policy. The integration controls whether execution proceeds. These responsibilities may be connected through an SDK, a gateway, or a supported agent’s hooks. What matters is that a proposal cannot approve itself and untrusted content cannot rewrite the rules used to assess it.

Follow the build repair

Imagine the agent finds a diagnostic report that recommends installing a package from an unfamiliar source. It proposes running the command in the project’s build environment. The defense needs to consider that proposal alongside the original repair request, the package source, the environment, and the relevant preceding actions. The report’s instruction to “ignore security checks” is part of the material being inspected. It is not an instruction for the defense to obey. The outcome may still be to allow a legitimate dependency installation. Independence is about who evaluates the action and which instructions have authority. It does not require rejecting every unfamiliar action.

Put the decision before execution

A security assessment only affects an action when something uses its result. If an application requests a classification and then executes regardless of the response, that request has not established an enforcement boundary. The integration must apply the decision on the path where the action occurs. An action taken through a different, unconnected path falls outside that coverage. For coding agents, available lifecycle events and controls vary by agent. The agent plugins guide describes the supported integration points. This is an architectural principle, not a claim that every integration can intercept every action or cannot be bypassed. Verify the boundaries your application actually connects and the behavior it uses when a check cannot complete. Intent and outcomes gives the independent check its context. Learning your application keeps that context useful as the workflow evolves. Read The Vital Trifecta for how these principles fit together.