● Open source
I build the controls, not just the slide.
Three tools for securing the agentic stack, each mapped to a public standard and each written
because the control I wanted to recommend didn't exist yet in a form anyone could run.
Identity, tools, and behaviour — the three surfaces where agentic AI actually
breaks. One tool each.
What these are
Working tools, built to make a control model runnable rather than aspirational. Each one
started as a question I couldn't answer for a customer with a policy document: which of
these identities is actually a crown jewel, which of these servers should I look at first,
did last week's prompt change reopen an attack path. They're deliberately deterministic
where they can be — a rules engine you can read and argue with beats a score you have to
trust.
What they aren't
Products. There's no vendor behind them, no support contract, and no claim of completeness
— they cover the surfaces I work on, in the environments I work in. If you run one and it
gets something wrong, an issue on the repo is the fastest way to make it better. Everything
here is MIT-licensed and built in the open.
Using one of these?
I'd like to hear about it — especially where it broke, or where the risk model didn't match
your environment. Issues and pull requests welcome; so is a direct message.