Shift Intent Left: Intent Contracts, Agency Budgets, and Drift Verification for Securing the Agentic Software Development Lifecycle
Abstract
“Shift left” moved security activities toward the earliest artifact of the software development lifecycle (SDLC): source code. Autonomous coding agents invalidate the premise that code is that earliest artifact. An agent equipped with a shell, a package manager, credentials, and tool connectors performs security-relevant actions — installing dependencies, reading secrets, calling external services — before any diff exists for a scanner or reviewer to inspect. Its behaviour is also steered by natural-language context (task descriptions, rules files, tool descriptions, issue text) that conventional pipelines neither version nor verify. We argue that in an agentic SDLC the earliest securable artifact is intent: the declared goal, scope, context, and authority under which an agent operates. We introduce Shift Intent Left (SIL), a lifecycle discipline that makes intent explicit, bounded, and verifiable before execution and checks execution against it afterwards. Shift Intent Left is the successor to shift left for agentic development: where shift left asks “what is in the code?” as early as possible, Shift Intent Left asks “what was the agent authorised to do?” before it acts. We contribute: the Shift Intent Left principle and its definition; a formal model comprising Intent Contracts, Agency Budgets, an admissibility predicate over agent actions, and a severity-weighted Intent Drift metric; a five-stage lifecycle (Declare, Budget, Sanitise, Verify, Learn) with a reference architecture; a threat model mapping four adversary classes to SIL controls, including the under-specified principal; a mapping of SIL onto NIST SSDF, OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications (ASI01–ASI10), NIST AI RMF, Zero Trust, and software supply-chain attestation (in-toto, SLSA); four falsifiable hypotheses, each with a full experimental design and explicit refutation criteria. SIL complements, rather than replaces, shift-left, shift-right, and runtime agent-security mechanisms: it supplies the reference specification those mechanisms currently lack. The appendices assume no background in formal methods. They provide a notation primer explaining every symbol used, a step-by-step expansion of the bounded-delegation proof, a fully worked example computing Intent Drift by hand for both an attacked and a benign run, and answers to recurring questions. Status. This is a conceptual and architectural contribution. It reports no empirical results; it specifies the experiments that would confirm or refute its claims. An empirical evaluation of Hypothesis H2 (Intent Drift as a detection signal under indirect prompt injection) is planned and will be published as a new version of this record. Supplementary material. The Intent Contract JSON Schema, a validator enforcing the invariants that JSON Schema cannot express, and example contracts are available at https://github.com/AnimeshShaw/Shift-Intent-Left.