GROW-S8 | Trust | Free & open

Security Zero Trust

Prevent unsafe actions, data leakage, and uncontrolled tool use while preserving useful autonomy.

7 skill artifacts · Gate-reviewed · GROW-S8 (Trust cluster)

What this module contains

7 reusable skill artifacts.

Each artifact is a standalone, versioned build deliverable — templates, registers, policies, specs, checklists, matrices, playbooks, and maps — wired to the rest of the GROW stack by explicit contracts.

Zero Trust Assumptions

policy · v0.1.0

This policy establishes the foundational default-deny posture for any agent that holds tool authority — the right to invoke connectors, write records, send communications, or spend money.

Builds on: s1-operating-context-canvas

Permission Architecture

spec · v0.1.0

This spec defines the structural permission model for agents with tool authority: the principal taxonomy, role definitions, least-privilege assignment rules, tool-scope boundaries, and sensitive-data authorization ceilings.

Builds on: t8-zero-trust-assumptions

Data Leakage Prevention

spec · v0.1.0

This spec defines the sensitive-data classification scheme, the rules governing when data of each class may move between contexts, the detection and blocking controls for prompt-injection and malicious-retrieval attacks, and the access-logging obligations that feed s3-provenance-metadata-schema.

Builds on: t8-permission-architecture, s3-provenance-metadata-schema

Tool Use Control List

matrix · v0.1.0

This matrix is the runtime permission table for every tool invocation an agent may attempt.

Contract: Produces C10 → Reliability + Provenance

Builds on: t8-permission-architecture, s1-threshold-escalation-spec

Action Safety Boundaries

spec · v0.1.0

This spec defines the safety controls applied to each action_class — the six categories by which tool calls are classified in the tool allow-list.

Builds on: t8-tool-use-control-list, s1-threshold-escalation-spec

Monitoring Incident Handling

playbook · v0.1.0

This playbook operationalizes the detection, response, and postmortem loop for security events in agents that hold tool authority.

Builds on: t8-tool-use-control-list, s1-monitoring-rollout-postmortem

Security Package

template · v0.1.0

Six fillable scaffolds for deploying a complete zero-trust security posture on an agent with tool authority.

Builds on: t8-zero-trust-assumptions, t8-permission-architecture, t8-tool-use-control-list, t8-data-leakage-prevention, t8-action-safety-boundaries, t8-monitoring-incident-handling

Build & gate status

Where this module stands.

Status

Gate-reviewed on 2026-05-29 against builders-evaluation-gate sections (a)–(e); promoted to reviewed.

How it composes

This module plugs into the four-cluster GROW stack (Systems → Execution → Trust → Coordination) through versioned interface contracts C1–C12. See the full wiring in the library registry.

Open access

GROW-S8 is free and open.

Every artifact, worksheet, and template in this module is free to use — no membership, no paywall.