DeferWithToken returns existing
handle on collision → wrong agent receives approval signal. Deterministic path
(sha256-based, safe) exists but Defer() fallback is weak.
TLSVerify is not set in config (or defaults false), all IDP token
verification — OIDC/Okta/Auth0 — proceeds without TLS certificate check.
LAN attacker can MITM the IDP endpoint, serve forged tokens, bypass agent
identity verification entirely. The pipeline trusts the forged identity.
RollbackReservedCost + DENY. But
go p.accountCost() (FARA-007) may already be reading the session
cost accumulator in a background goroutine. Under high concurrency: concurrent
PERMIT sees rollback-in-progress cost → budget undercount → over-permits spend.
Reserve-confirm-rollback is not a true atomic transaction.
sess.CurrentCostUSD() returns pre-cost value.
Budget check [5] sees stale state → allows second call that should have been denied.
Classic TOCTOU on cost accounting under concurrent load.
faramesh/Openclaw-Plugin already ships.openclaw plugins install @faramesh/openclawdynamic() type for runtime embeddings.
12/13 T: benchmark for type narrowing. Ecto pgvector-elixir v0.4 already supports halfvec/sparsevec/hybrid RRF.
Faramesh governance layer integrates via MCP gateway — same path as laam-pip.
phases block maps directly to SOSTLE layers. Phase transition rules =
SOSTLE gate conditions. Budget blocks = basal/bolus limits from Shadow Admiral doctrine.
Defer/Approve = ARB1 pending → ratified. DPR WAL = PEMCLAU session ingest.