8. Tools and safety boundaries

If you only remember 3 things 1. Every tool is a narrow, validated capability: Splunk client behind a Protocol, code search that never executes repo code, a fix validator that rejects out-of-candidate and no-op fixes, and a GitHub tool that can only branch/commit/push inside one repo path. 2. The LLM never gets a raw shell or a free-form file write — it returns JSON, and code decides what is legal (backend/app/tools/issue_fix.py, backend/app/tools/github_tool.py). 3. Threat model: prompt injection via log content is mitigated at two layers (prompt + validation + human gate); a malicious fix proposal is constrained but not fully mitigated (the human is the backstop); token-in-URL push is a known, unmitigated weakness we disclose.

The four tools

1. Splunk client — backend/app/tools/splunk_query.py

2. Code search — backend/app/tools/code_search.py

3. Fix validation — backend/app/tools/issue_fix.py

The LLM proposes; code disposes. propose_fix() enforces:

Check Failure
No candidate files FileNotFoundError
file_path not among candidates ValueError("The fix agent selected a file outside the searched candidates.")
fixed_content empty or identical to original ValueError("The fix agent did not produce a code change.")

Then it builds a unified_diff via difflib (a/{path} → b/{path}) and returns a ProposedFix dataclass. The candidate-file restriction is the key boundary: the model cannot touch any file the search didn't surface — and the search already excluded demo/config paths.

4. GitHub tool — backend/app/tools/github_tool.py

Threat model

T1. Prompt injection through log content — MITIGATED (layered)

T2. LLM proposes a malicious or destructive fix — CONSTRAINED, human is the backstop

T3. Token leakage — PARTIALLY MITIGATED, disclose honestly

T4. The LLM exfiltrating data via the fix — LOW / structural

"Is this really an agent?" — the honest framing

The pipeline nodes are orchestrated steps (deterministic routing, no tool selection). The genuinely agentic parts are the three LLM nodes that choose: rca chooses a diagnosis from evidence, recommend chooses a next step, and the fix agent chooses a file and an edit from candidates. The fix step is the most agent-like: perception (RCA + code) → decision (which file, what change) → action (validated branch/commit/push). Say it exactly like that — it's defensible and true.