Skip to content

feat: Add NTI Guardrail Middleware for post-quantum agent security - #7817

Closed
abisheakp197 wants to merge 1 commit into
crewAIInc:mainfrom
abisheakp197:main
Closed

abisheakp197 wants to merge 1 commit into
crewAIInc:mainfrom
abisheakp197:main

Conversation

@abisheakp197

@abisheakp197 abisheakp197 commented Sep 29, 2026 •

Copy link
Copy Markdown

Description

#7818

This PR introduces NTI (Neutral Trust Infrastructure) as an optional security guardrail for CrewAI agents.

As AI agents begin executing real-world actions, verifying their identity and policy bounds in real-time becomes critical.

This integration adds NTIGuardrailMiddleware which uses the ube-foundation Python SDK to enforce:

  • Post-Quantum Cryptographic (PQC) signatures (Dilithium5/Kyber1024)
  • Zero-Trust capability bounds (via TrustEngine.evaluate)
  • BFT multi-agent consensus boundaries
  • Immutable Merkle-chained audit logging

Installation

pip install ube-foundation

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> New authorization path for tool execution depends on external `ube-foundation` behavior; misconfiguration or engine bugs could block or allow tools incorrectly, though scope is limited to the new optional module.
> 
> **Overview**
> Adds **`NTIGuardrailMiddleware`** in `crewai/security/nti_guardrail.py` as an optional NTI layer on top of the **`ube-foundation`** SDK (`TrustEngine`, `PqcKeyPair`).
> 
> On init it binds an **`agent_id`**, spins up a **`TrustEngine`**, and generates a post-quantum key pair. **`grant_capability`** registers capabilities for that agent via **`engine.grant`**. **`verify_tool_execution`** builds a JSON request for a tool name and input, signs the canonical payload with PQC, sends it to **`TrustEngine.evaluate`**, and returns whether the decision is **`Allow`**.
> 
> Nothing in this PR wires the middleware into CrewAI agents or tool hooks; it is a standalone security helper module.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit b10c97d0a8156daf0bf62131767c027e67854d66. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

@github-actions

Copy link
Copy Markdown
Contributor

Thanks for the pull request.

First-time contributors need an associated open issue before we can review a PR.

  1. Open an issue with a template, or pick an existing open one.
  2. Open a new PR (or reopen this one) whose title or body mentions that issue, for example #123.

See the contributing guide.

@github-actions github-actions Bot added the needs-issue First-time contributor PR closed because it did not mention an open issue label Sep 29, 2026
@github-actions github-actions Bot closed this Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 6a09ff89-58d9-4b0e-8a3d-c6875c717721

📥 Commits

Reviewing files that changed from the base of the PR and between a0d16dd and b10c97d.

📒 Files selected for processing (1)
  • crewai/security/nti_guardrail.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want fixes drafted automatically? Bugbot Autofix can create code changes for findings. A team admin can enable Autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit b10c97d. Configure here.

req["pqc_public_key"] = self.pqc_key.public_key_hex()

decision = json.loads(self.engine.evaluate(json.dumps(req)))
return decision.get("decision") == "Allow"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Guardrail module is not packaged

High Severity

NTIGuardrailMiddleware was added under repository-root crewai/security/ instead of the installable package at lib/crewai/src/crewai/security/. It is never exported or imported, so the guardrail cannot be used after installing crewai.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit b10c97d. Configure here.

def verify_tool_execution(self, tool_name: str, tool_input: dict) -> bool:
import json
req = {
"id": f"req-{abs(hash(str(tool_input)))}",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Request IDs are not unique

Medium Severity

Request id values are derived from hash(str(tool_input)). Python salts string hashes per process, and the same tool_input always produces the same id, so identifiers are neither stable across runs nor unique per tool call.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit b10c97d. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-issue First-time contributor PR closed because it did not mention an open issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant