Open-Source Runtime Security Layer Keeps Credentials Out of AI Agents

Technical-Spread-368 · reddit · 2026-10-01

A Reddit user released Pryxor, an open-source runtime security layer that sits between an AI agent and the systems it can act on. Instead of calling tools directly, the agent sends tool calls to Pryxor, which authenticates the agent via API key, validates arguments against the tool's JSON schema, evaluates the call against a deterministic policy, returns APPROVED/HOLD/BLOCKED, and — if approved — executes the call itself with credentials the agent never sees. The HOLD case is the author's focus: the action may be legitimate but needs a human decision, so it waits.

The motivation is a common anti-pattern: give the agent a broad-permission token and hope the model uses it correctly. But prompt injection and hallucination are normal behavior of a probabilistic system; when the model is your security boundary, every failure is an incident. The alternative: don't give the agent the credential, give it an intention, and let a deterministic layer decide whether that intention becomes an action.

The author is candid about limits: it is not an LLM firewall, does not scan prompts or outputs, does not detect prompt injection (it bounds consequences), cannot protect a path that bypasses it, and is single-node with SQLite, no multi-tenancy, RBAC or SSO; TLS is out of scope. Apache 2.0, with a quickstart and a cloneable sandbox demo; the author is in the comments for feedback.

Original post →

More from coding & agent

coding & agent channel →