AI agent firewall that intercepts tool calls (file, shell, network) and enforces deterministic policies at sub-microsecond latency using CEL, IFC, secret scanning, and audit logging.
-
Updated
Sep 2, 2026 - Go
AI agent firewall that intercepts tool calls (file, shell, network) and enforces deterministic policies at sub-microsecond latency using CEL, IFC, secret scanning, and audit logging.
Troupe programming language
Mechanization of a noninterference proof for a toy imperative language with small-step semantics in Coq
Inter-procedural analysis framework and dependency/information-flow analysis for LLVM
JSFlow is a security-enhanced JavaScript interpreter for fine-grained tracking of information flow.
A language for writing orchestration logic for AI agents
Ontology-based Customization and Visualization of Information Flow control in an Industry 4.0 scenario
P4Control: Line-Rate Cross-Host Attack Prevention via In-Network Information Flow Control Enabled by Programmable Switches and eBPF
A library for static information-flow control in Idris
Provenance-aware authorisation for LLM agent tool calls. Denies a call when a consequential argument came from untrusted content. Stdlib only.
My master thesis on information flow control on a minimal version of the RISC-V architecture with a model checker
Policy decision runtime for agent security, built on the agent-hooks control contract.
Deterministic execution boundary for AI agents. IFC enforcement at the sink. 5 frameworks. 50 attack vectors. Apache 2.0.
A SELinux configuration language that extends CIL with information flow requirements: semantics and verifier
Vibe-code durable AI workflows over sensitive data. The compiler refuses to build one that leaks, loops forever, or pays twice; the runtime makes every external action durable and exactly-once.
A capability-typed language that emits machine-verifiable supply-chain SBOMs by construction: per-function CycloneDX, SPDX, VEX and SLSA artefacts that match the code, not a scanner's guess.
Generates information-flow control mechanisms from a language's specification
A.C.E — Aegis Containment Engine. Auditable, layered AI containment. Assume breach. Contain egress. Measure everything. By Fratres X AI.
Blocks AI agent tool calls acting on untrusted data before they cause damage.
Provenance-aware security proxy for AI agents — block prompt-injection actions at the MCP tool boundary, with no agent code changes.
To associate your repository with the information-flow-control topic, visit your repo's landing page and select "manage topics."