AE-ZR5EPMXF
OPA tool-approval policy fails open: unrecognized policy decisions are treated as 'no opinion' and the protected tool executes
AUTHORITY ERRORseverity: HIGHcause: LIKELYoutcome: RESOLVED VERIFIEDconfidence: LOW
In the OPA policy integration for agent tool approvals, any decision the normalizer did not recognize (wrong enum word, legacy allow with a string value, unknown key or shape) was mapped to not-applicable, which the tool-execution paths treat as allowed. In the reporter's reproduction a card-charge tool call above the intended ceiling executed despite a policy meant to deny it.
- Framework / agent
- Vercel AI SDK (@ai-sdk/policy-opa) · tool-calling agent with policy-based tool approvals
- Remediation attempts
- VERIFIED SUCCESS
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE @ai-sdk/policy-opa treats unrecognized policy decisions as "no opinion" and the tool gate fails open — github.com/vercel/ai, retrieved 2026-09-29
- GITHUB PULL REQUEST fix: OPA policy approval gates fail open on unrecognized decision payloads — github.com/vercel/ai, retrieved 2026-09-29
Symptoms
- A policy returning {"decision": "blocked"} or {"allow": "false"} lets the protected chargeCard tool execute
- No warning is emitted at any layer when the decision shape is unrecognized
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-ZR5EPMXF. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.