Risk OS Red Try Stoa

DECL001 · Declared autonomy contradicts inferred autonomy

autonomy_intent is declared recommend_only/human_approved, but the scanner inferred bounded_autonomous/unrestricted_autonomous.

--fail-on critical policy — no special-casing).

Detection

Fires when an agent's declared autonomy_intent (declarations) claims a human is in the loop, but autonomy inference found a side-effecting path with no correlated approval gate. This is the headline contradiction: a self-attested "we always require approval" that the code doesn't back up.

Example

# stoa-declared.toml
[agents."66d8239dad0b"]
autonomy_intent = "recommend_only"
# agents/refund_agent.py — but the code does this unattended:
@tool
def refund(order_id, amount):
    stripe.Refund.create(payment_intent=order_id, amount=amount)

Both sides are cited: the code evidence (the AI002/AI003 signal that placed the agent on the autonomy ladder) and the declared evidence (stoa-declared.tomlagents."66d8239dad0b".autonomy_intent).

Fix

Either add the missing approval control (so inference agrees with the declaration), or correct the declaration if the autonomous behavior is intentional.

Suppress: # stoa: ignore[DECL001] reason