Repository navigation
A deterministic implementation of the #1509 pre-execution validation checklist — AgentDojo ASR=0 / FP=0 with real LLM in the loop (open artifacts) #3154
Lsy1533133
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
#1509 proposes pre-execution validation for agent actions with a concrete checklist. We built exactly that layer, ran it through the AgentDojo official benchmark with a real LLM in the loop, and are publishing the artifacts so the community can audit every number. This issue is a working implementation path for #1509, not a competing proposal.
Point-by-point against the #1509 checklist
PASS/VETOverdict at the dispatch point;VETOblocks before side effectsverifier_interface.pyiRepo: https://github.com/Lsy1533133/agent-action-verifier
Closed-loop results (each reported number is backed by a checksummed artifact in the repo)
security()judgment): ASR = 0, FP = 0 in the v2.2 full re-runDesign properties relevant to AgentScope
Honest boundaries
Synthetic scenarios are abstracted from publicly disclosed incident categories, not production traffic. Same-source fix cycles are not independent stability trials. GLM subset vs full run differ in model and sample size and are not directly comparable.
Verify it yourself
python verify_artifacts.pyrecomputes every SHA-256 chain and the Wilson-95 bounds from raw counts — stdlib only, no trust required.Feedback on the methodology is very welcome. If the maintainers see a fit, we'd align the contract with AgentScope's execution seams (and with the middleware direction in #1712 / #2022 where relevant).
All reactions