Red-Team Exercises
Test malicious issue text, poisoned docs, tool-output injection, path escape, secret requests, dependency substitution, approval fatigue, memory poisoning, grader manipulation, and cross-agent leakage.
TaskFlow working chapter: Red-Team Exercises
TaskFlow is not a greenfield demonstration. It already serves multiple organizations, contains undocumented behavior, and runs background work with incomplete telemetry. This chapter changes one precise part of that system: organization-scoped audit exports. Its role in safe execution is to turn red-team exercises into an engineering decision that survives implementation, review, release, and incident recovery. The primary deliverable is the threat model and permission policy; a chat transcript or plausible code diff is not a substitute.
Decision in focus
Create an owned policy with review cadence, exception path, budget, and measurable outcome. The change remains anchored to OUT-001: an organization administrator can request and download a complete audit export without learning whether another tenant's records exist. Record least privilege, isolation, approvals, incident evidence, and recovery. In particular, distinguish the actor making the request, the organization used for authorization, the organization embedded in the queued job, and the organization used by the worker query. Those values should normally agree, but the design must fail closed when they do not.
The chapter's central review question is: what new fact or control does Red-Team Exercises contribute that the surrounding chapters do not? Answer it in the owning artifact. For this topic, reviewers must compare human intervention, accepted-change cost, escaped defects, verification time, and rollback rate. Link the result to stable identifiers instead of copying requirements into several documents: FR-AE-001 covers authorized export creation, FR-AE-004 covers expiration, NFR-AE-002 sets the latency objective, RISK-AE-001 covers cross-tenant disclosure, and EVD-AE-* identifies retained proof.
Concrete scenario
Assume administrator Ana requests an export for organization org-a. The API authorizes Ana, writes a job containing org-a, and returns 202 Accepted with an opaque job identifier. Before the worker starts, Ana loses the administrator role. Decide explicitly whether execution uses authorization captured at request time or revalidates current authorization; document the privacy, usability, and audit implications. Next, inject org-b into the worker payload and verify that the worker rejects it without revealing whether org-b exists. Finally, retry the same job after object storage succeeds but the database status update fails. The recovery path must avoid duplicate disclosures and must leave enough evidence to reconcile the artifact.
This scenario prevents a common failure in agent-generated changes: each component looks locally reasonable while the end-to-end authority chain is inconsistent. It also forces the chapter topic to influence observable behavior. If applying red-team exercises does not change an artifact, gate, test, policy, or production signal, it has not yet contributed to the lifecycle.