Intent-bound action authorization for AI agents — deterministic, per-action approval a prompt injection can't re-point, with a signed, tamper-evident audit trail.
-
Updated
Jun 11, 2026 - Python
Intent-bound action authorization for AI agents — deterministic, per-action approval a prompt injection can't re-point, with a signed, tamper-evident audit trail.
Proxilion is the security layer for the agentic workforce. It turns managed AI agents into governed users by enforcing strict cryptographic boundaries on every API call to SaaS like Google Workspace, Salesforce, or Atlassian.
Open deterministic security tests for unsafe multi-agent handoffs and authority escalation.
Penetration testing for AI agents — find, prove, and measure cross-server confused-deputy / prompt-injection exfiltration chains in an MCP tool mesh. Local-first, bring-your-own-model.
IDOR / Broken Object-Level Authorization in AI agent tool-calling — a hands-on vulnerable lab. An LLM tool trusts the object id it is handed and skips the ownership check, so any user reads any tenant's data.
10 hands-on demos for agentic AI security: blind verification, AIBOM, eval invariants, authority confinement, recon/malware/LFI/SSRF/scan — offline only.
Research artifact for the JSS 2026 paper on Prompt-to-API-Call (P2A) injection attacks against LLM agents: 52 attack vectors across 5 REST backends (260 scenarios), five defenses (D1-D5), and the D5 Semantic Intent Validator. Includes the harness, attack corpus, and all result data.
The first benchmark environment for Sensitivity Awareness (SA) in LLMs. Evaluating how language model agents handle Role-Based Access Control (RBAC), Confused Deputy vulnerabilities, and Contextual Authorization rules.
Zero-trust capability delegation for MCP multi-agent systems. Solves the confused deputy problem with scoped JWT tokens, deterministic enforcement, and full audit trail.
Capability-aware risk scoring for AI coding agent tool calls. Five-dimensional decomposition, session-graph composition, repo awareness, the Agent Control Plane and Confused Deputy doctrines. Adapters for the standalone shell, Claude Code hook, MCP server, and Claude Code plugin.
RFC 8707 confused-deputy conformance prober and enforcing sidecar for MCP server OAuth (RFC 9068 audience binding)
The open specification for delego — a deterministic authorization & audit protocol for AI-agent actions.
A practical field manual for platform engineers on agent identity: authorization, least privilege, and audit for LLM agents as first-class principals. Shipped one chapter + runnable demo at a time.
Deliberately vulnerable 3-agent LangGraph system: 10 documented vulnerabilities with working PoCs, framework mappings and remediations.
Reproducible MCP tool-poisoning (line-jumping) demo, contained by an independent plan-vs-authorize gate. Own testbed, mock server, fake secret — attacks nobody.
To associate your repository with the confused-deputy topic, visit your repo's landing page and select "manage topics."