CITATION — REFERENCE ENTRY

security-confirmation · wang2025sdk

Revision 6d71ff5b-5e89-49a3-9279-13588b129b16 · 8/29/2026, 11:17:33 AM UTC
Citation
wang2025sdk
Claim ID
security-confirmation
Assertion
The SDK separates risk assessment from enforcement using two components. A security analyzer rates each proposed tool call as low, medium, high, or unknown risk; a confirmation policy decides whether user approval is required. When approval is needed the agent halts in a waiting-for-confirmation state until the user approves or rejects, and may retry with a safer alternative after rejection. The policy can be changed during a session. A built-in pair blocks actions above a configurable threshold, defaulting to high.
Locator
section: 4.9
Available in