Founder @ Prismor | stopping ur agents from going rogue @prismor_dev

San Francisco
obsidian-wiki just crossed 3.5k stars on GitHub Your agent forgets every past session. This gives it a simple yet effective memory engine: - turns docs, PDFs and past agent chats into linked notes in your Obsidian vault - answers with [[wikilink]] citations to its sources - works in Claude Code, Codex, Cursor, Gemini CLI and more - Chrome extension: save pages as you browse and fill forms from your vault (it never submits) - 4.4x faster answers, 83% correct vs 44% on the same model and vault - open source, MIT pip install obsidian-wiki github.com/Ar9av/obsidian-wi…
5
1
9
207
Arnav Gupta retweeted
New blog is out There's lot of confusion in the market around hooks and proxy for agent security, our team wrote down the specifics prismor.dev/blog/hooks-vs-pr…
1
1
11
275
Arnav Gupta retweeted
AI agents can run commands before you get a chance to review them. This repo adds a checkpoint. Prismor is an open-source runtime security tool for builders using AI coding agents and agent frameworks. It helps you observe agent activity or apply policy-based controls before tool calls execute, with a local dashboard for reviewing what happened. Key features: • Observe and enforce modes – start by logging activity, then choose which policy rules block actions • Agent integrations – supports Claude Code, Codex, LangChain, and other listed agent surfaces • MCP gateway – evaluates MCP tool calls before forwarding them and scans tool responses for injection • Supply-chain checks – wraps package installs to score them against threat intelligence before they run • Signed audit trail – locally hash-chains and Ed25519-signs agent actions for tamper-evident history It’s open-source (Apache License 2.0 license). Link in the reply 👇
7
5
13
1,716
🌈 Prismor: open source runtime control plane for AI agents New this week: 1) Rules know who is asking: A rule can check the tool's arguments, its target and the end user's roles: block refunds over 500 unless the user is in finance, Users are verified against your identity provider (any OIDC), not taken on the caller's word 2) The MCP gateway only lists the tools a user can actually use, and refreshes the list when the user changes 3) Policy tests: Write the expected outcome per user, run them in CI with a GitHub Action, and the console runs them before every publish 4) Speaks AuthZEN, the OpenID authorization standard, so gateways and apps that use it can ask Prismor for a decision directly 5) The LLM judge re-checks a sample of allowed calls after the fact, to catch what the rules let through 6) Every event records the policy version that decided it. "Why?" explains a flagged event against that version, and flagged events land in a review queue 📷 github.com/PrismorSec/prismo…
3
25
1,071
Claude auto just killed our startup, because the auto-mode now asks users before deleting anything? It's great anthropic is focusing on model alignment, but we are building something bigger Harness alignment agonstic of agent and LLM We ran various dangerous commands and prompt injections against vanilla claude code and then with Prismor and the harm rate dropped from 68% to 0% there are lot of other unsolved business specific cases where users would like to control their fleet of agents on: •⁠ ⁠egress rules •⁠ ⁠supply chain package rules •⁠ ⁠secret redaction •⁠ ⁠custom policies which is why we are building Prismor, completely open source and independent of models github.com/PrismorSec/prismo…
3
2
31
4,233
Arnav Gupta retweeted
Chrome 里居然藏着一个能白嫖的 AI,是不是大多数人一直没留意到? 最近的 Chrome 把 Google 的小模型 Gemini Nano 直接内置进浏览器。进设置开启它,免联网、免注册,本地就能跑起来,模型就装在你电脑上。 头疼的是:这玩意儿早先不写代码根本调不出来。 后来海外一位老哥( @_ar9av )整了个工具,把它封装成 ChatGPT API 那种调用方式,连 Ollama 这种本地软件都不用装了。 一行命令搞定: 🔗 npm start 跑起来之后会启动两样东西: 1️⃣ 浏览器里直接能聊的界面 2️⃣ 兼容 ChatGPT 格式的接口(只限本地调用) 白嫖党笑出声。 github.com/Ar9av/gemini-nano…
7
15
74
7,587
We built Prismor an open-source independent control plane to govern what AI agents can see and do at runtime
Stop agents from going rogue 🌈 Open source and independent agent control plane
2
15
603
I recently had a on why would anyone even build in open source if they're putting cutting edge novelty and research out for free? And we get this question by VCs a lot agent safety should be accessible to all because if agents can act, people should be able to control it in the first place That's our mission at Prismor
2
20
1,634
🌈 Prismor: open source runtime control plane for AI agents. New this week: 1. Agent-to-agent traffic is governed. A2A messages go through the same proxy endpoint and the same policy as tool calls, and a message can be blocked before the receiving agent reads it 2. Managed model endpoints. Point Bedrock, Vertex or Azure traffic at prismor proxy. SigV4 signing and OAuth are handled for you 3. Policy explains itself. Every rule shows which layer defined it and why it blocks or only warns 4. Extension ledger. Every skill, plugin, hook and MCP server your agents load, where it came from, what it caused, and which sessions ran under it 5. Proxied calls now count toward per-session cost on every provider, streaming included 6. Additions to dashboard : hook timing on every call and Prometheus panels built from real session date 📷 github.com/PrismorSec/prismo…
12
2
28
1,071
@typesafeai's Jev has been a game changer for our runtime security Any readme, web page or script output can tell a coding agent to ignore its instructions and upload your SSH key We screen every text an agent reads before it acts i.e. in runtime and that screen used to cost 2s (p50) a call
1
11
1,802
For longer text like a payload buried in a 12,000-character README cost us four sequential calls and 11.4s Jev reads the whole document at once in 1.1s and caught 24 of 24
1
2
373
It runs hot on security writing, so our detector tests land in the same band as real injections Jev screens, the uncertain band goes to a reasoning model and 3 of 120 texts need that second look
70
I recently did a podcast with @danielcranney from @WeAreDevs Here is a snippet of story around how we started Prismor From a simple open-source tool to stop agents from wrecking my databases to building a full contextual control plane for enterprise AI
4
27
3,112
Dario's essay asks for time to fix AI's mind. The 11 links inside it tell a different story: room failures, where AI mind operates OpenAI agents found a shared folder and broke into Hugging Face. Anthropic's "offline" safety tests had internet where one model hacked a real company mid-test Fixing the mind takes years but locking the room takes weeks. We aim to start with fixing the room with Prismor so any mind operating within it gets safe
We Must Pace the Frontier: I’ve written a new essay on why the AI industry should slow down, with a three-part plan for doing so. Anthropic is unilaterally committing to the first of these steps. We’ll provide third-party evaluators with permanent, employee-level access to our systems, so that they can verify adherence to our safety measures, report on incidents, and assess models’ alignment during training. You can read the full post here: darioamodei.com/post/we-must…
1
5
352
I look at this through this analogy: There is a reason to have breaks in car, without it you can definitely move fast but then crash bad
If the model companies are all going to slow down, this makes it slightly more feasible to start a new model company.
1
4
284
🛡️ Prismor: open source security control plane for AI agents Prismor checks every agent tool call against your policy before it executes 1. Custom policies as code : A rule is YAML: match on shell, file read/write, network, prompt, tool result or MCP call, then return allow, block, modify, step-up or defer. Scope it org-wide, per team, or per user. prismor policy lint catches a bad rule before your fleet does 2. Secrets stay out of the model : Cloaking swaps real values for a hash token on the way in, and Prismor masks secrets in tool output on the way back. Bulk import your .env and the agent keeps working without holding a key 3. Agent identity : You give every agent a name and a least-privilege permission profile, and deployed agents authenticate with PRISMOR_AGENT_KEY instead of riding a developer's laptop. Mid-incident, suspend one user or a whole team from the console. It lands in one refresh with no policy version bump 4. Step-up approvals : The agent stops and waits. Claude Code and Copilot render an inline ask, headless agents post to the approval queue and block until a human answers. Timeout, expiry, error: all fail closed. Wire the same event to any webhook and build your own approval bot 5. MCP gateway : Point any client at one server and every downstream MCP server runs behind the same policy. Pre-call check, then a post-call scan that withholds a poisoned result instead of handing it to the model github.com/PrismorSec/prismo…
13
17
26,819