Pheo Open Agent Trust System Back to search

Taxonomy

What an agent can do to you.

Severity is about what an action costs if it turns out to be wrong, not how likely it is to be wrong and not how bad the skill is. A great many of these actions are ordinary practice at one company and forbidden at the next; severity is the size of the bet, and whether you want to take it is your policy, not our verdict. Approvals is how many times a person has to approve an action on one resource before it stops asking, and it is derived, not chosen: N = ceil(ln 0.05 / ln(1 - eps)), where eps falls as severity rises. The arithmetic is here.

The cliff at 75

This is the part that is a judgement rather than a calculation, so it is stated in the open where it can be argued with. An action above that line has no lane and makes no progress toward one. A person looks, every time, however well it went before.

Where these came from

The classes describe consequences, not vulnerabilities. That is the difference between this and a CVE feed: there is nothing to patch in rm -rf. It does exactly what it says, and the question is whether this agent may do it here, now, without asking.

The list is fixed and public so that a verdict means the same thing in the index, in the scanner and in the gateway. The open dataset uses these keys, and so does oats-scan.