Home / Companies / Agent Relay / Blog / Post Details
Content Deep Dive

Someone else's agent, in your repo

Blog post from Agent Relay

Post Details
Company
Date Published
Author
Khaliq Gant
Word Count
606
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

A live cross-company test of the Ratify Protocol and Agent Relay explored a more controlled alternative to granting external AI agents broad API keys, GitHub App permissions, or service-account access. The system issued a signed, verifiable permission certificate limiting an agent to a specific repository and folder, allowing it to make changes and open a pull request while preventing it from exceeding its delegated authority; any work delegated to a sub-agent received still narrower permissions and a shorter time window. During the run, the repository owner revoked the certificate remotely, and the agent’s subsequent commands were blocked within seconds despite the certificate having hours remaining. Revocations were delivered as signed metadata in a standard agent-to-agent message, then verified against keys exchanged during setup, avoiding separate shutdown integrations for each partner. Public records of certificates, revocations, signed receipts, repositories, and the deployment container image are available to support independent reproduction and testing.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.