Open-Source Runtime Security Layer Keeps Credentials Out of AI Agents
Technical-Spread-368 · reddit · 2026-10-01
A Reddit user released Pryxor, an open-source runtime security layer that sits between an AI agent and the systems it can act on. Instead of calling tools directly, the agent sends tool calls to Pryxor, which authenticates the agent via API key, validates arguments against the tool's JSON schema, evaluates the call against a deterministic policy, returns APPROVED/HOLD/BLOCKED, and — if approved — executes the call itself with credentials the agent never sees. The HOLD case is the author's focus: the action may be legitimate but needs a human decision, so it waits.
The motivation is a common anti-pattern: give the agent a broad-permission token and hope the model uses it correctly. But prompt injection and hallucination are normal behavior of a probabilistic system; when the model is your security boundary, every failure is an incident. The alternative: don't give the agent the credential, give it an intention, and let a deterministic layer decide whether that intention becomes an action.
The author is candid about limits: it is not an LLM firewall, does not scan prompts or outputs, does not detect prompt injection (it bounds consequences), cannot protect a path that bypasses it, and is single-node with SQLite, no multi-tenancy, RBAC or SSO; TLS is out of scope. Apache 2.0, with a quickstart and a cloneable sandbox demo; the author is in the comments for feedback.
More from coding & agent
- Building a million-page OCR pipeline with a 500GB RAM used server plus LLM extraction — oilmutt · 2026-10-01
- Agentic coding lowered the cost of change and raised the cost of holding invariants — _AustinCalvert_ · 2026-10-01
- Developer wakes up to 6.5 hours of agent-completed work — calls it 2 weeks of his time — therealdanvega · 2026-10-01
- Ex-OpenAI Researcher Launches Jev: A System One Model for Structured Decisions, 100x Faster — KhuyenTran16 · 2026-10-01
- Jev vs PydanticAI: control the decision before the model responds, with confidence scores — KhuyenTran16 · 2026-10-01
- Dev builds MCP server to fetch podcast transcripts as a high-quality info source — vista8 · 2026-10-01