Should coding agents scan tool results for prompt injection before they hit the context?

PatronusProtect · reddit · 2026-09-09

Patronus proposes a harness plugin that inserts a security hook between tool results and an agent's context: a local semantic threat/injection scanner (with optional API fallback) that redacts only suspicious sections instead of discarding whole results. Next steps include maintaining security context across multiple tool calls. They're asking developers whether they'd install it as a Codex plugin and what false-positive/latency thresholds are acceptable.

Original post →

More from coding & agent

coding & agent channel →