CSL-Core: open-source tool to inventory AI agents, map risk chains, and guard tool calls
Longjumping-End6278 · reddit · 2026-10-09
A developer released CSL-Core, an open-source, locally-run guard for AI agents with real tools (refunds, shell, file writes). Prompt-based limits like "never refund more than $500" hold most of the time, not always, and leave no audit trail.
Key approach:
- Inventory first: read-only scans for coding assistants, MCP servers, LangChain/OpenAI Agents/CrewAI tools, cron jobs and webhooks, classifying each tool as read/write/execute/spend/delete.
- Risk is in chains: it maps how agents connect (e.g., a web-reading agent editing files of a root agent) and highlights the single rule that breaks each chain.
- Enforce before the function runs: per-call spending ceilings, command allowlists, folder-scoped writes; policies are checked with the Z3 solver for contradictions; rules are invisible to the model.
- Guards break in glue code: resolve paths before prefix checks, compare path components not strings, parse commands and reject ;, |, &&, $(), backticks, and compare parsed hostnames not substrings.
- Log before you block: a log mode records allow/would-block for tuning; unknown tools are denied by default, and CI fails on unregulated spend/execute tools.
Honest limit: default rules are strict and need tuning on busy agents.
More from coding & agent
- Kernel ships official Replit Agent connector, pairs with Stripe for agentic payments — jeff_weinstein · 2026-10-09
- Open-source GodTerm puts every Claude Code and Grok account in one command center — Daniel_Farinax · 2026-10-09
- As verifiable model capabilities commoditize, engineers have 4 ladders left to climb — himanshustwts · 2026-10-09
- TRAE's big update: from coding assistant to orchestrating agent fleets, plus 5 practices — dotey · 2026-10-09
- Five questions every agent tool description must answer before it gets called — usehive · 2026-10-09
- open-knowledge: AI-native markdown IDE with Claude and Codex side-by-side hits 4.4k stars — tom_doerr · 2026-10-09