Skip to main content
Policy-as-Code Firewall

Guardian Firewall

An agent-action firewall prototype for exploring dynamic rules, Python AST checks, and content heuristics before tool execution.

GUARDIANCONSOLE

BROWSER DEMO
Payload Input
Security Scan Trace

Awaiting Payload
for Inspection

EXTERNAL API: OFFLINEGATEWAY: BROWSER ONLY
Python rules: modeled
Content patterns: modeled

Policy Engine

Enforce business logic policies (e.g., "No refunds > $100") using a dynamic rule engine.

AST Analysis

Statically analyze generated code to detect dangerous imports, syscalls, and RCE attempts.

Content Heuristics

Apply Sentinel-inspired regex heuristics for prompt injection, prompt leakage, and PII-related terms.

The Defense-in-Depth Architecture

Guardian

Action & Policy Firewall

Future Integration

Sentinel

Planned Service Integration

Guardian validates action structure with Python rules and AST checks, then applies a small set of local content patterns. A real Sentinel service handoff remains future integration work.

Validation Boundary

Concrete analyzers, early security maturity.

Guardian demonstrates a useful interception contract locally. It has not undergone adversarial evaluation, security review, load testing, or production validation.

4/4Core cases verified

Refund policy, dangerous Python, injection pattern, and safe action paths behave as expected locally.

0Automated tests

The pytest configuration exists, but the repository currently contains no test files.