Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md). Findings are hypotheses until reproduced on current main (WO-00).

Finding: Production entry re-exports the Boss app; chat and direct-action handlers have no auth dependency and the deploy config requests public access [R21]. Files: miz-oki-adk-agents/boss/app.py, miz-oki-adk-agents/app/main.py; deploy workflows carrying allow-unauthenticated/allUsers (see .github/workflows/deploy-governance-services.yml and others found in WO-00). Fix: explicit public/private route inventory; auth dependency on chat and direct-action; deploy config no longer requests public invoker unless the route inventory says so. Acceptance: anonymous request to direct-action → 401 in test client; route inventory committed; IAM invoker policy verified by OPS (read-only check). Depends on: WO-00.

← All docsView source on GitHub →