Guardian Firewall
An agent-action firewall prototype for exploring dynamic rules, Python AST checks, and content heuristics before tool execution.
GUARDIANCONSOLE
Awaiting Payload
for Inspection
Policy Engine
Enforce business logic policies (e.g., "No refunds > $100") using a dynamic rule engine.
AST Analysis
Statically analyze generated code to detect dangerous imports, syscalls, and RCE attempts.
Content Heuristics
Apply Sentinel-inspired regex heuristics for prompt injection, prompt leakage, and PII-related terms.
The Defense-in-Depth Architecture
Guardian validates action structure with Python rules and AST checks, then applies a small set of local content patterns. A real Sentinel service handoff remains future integration work.
Validation Boundary
Concrete analyzers, early security maturity.
Guardian demonstrates a useful interception contract locally. It has not undergone adversarial evaluation, security review, load testing, or production validation.
Refund policy, dangerous Python, injection pattern, and safe action paths behave as expected locally.
The pytest configuration exists, but the repository currently contains no test files.