Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

I built a firewall for agents because prompt engineering isn't security

Details

External ID
46683661
Source
HN
Company
—
Product
Claw Patrol, a security firewall for agents
Website domain
github.com
Launched
Jan. 19, 2026
Cohort
—
Upvotes
7
Upvotes percentile
0.3544137022397892
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

Hi HN, I’m the creator of Cordum.I’ve been working in DevOps and infrastructure for years (currently in the fintech/security space), and as I started playing with AI agents, I noticed a scary pattern. Most "safety" mechanisms rely on system prompts ("Please don't do X") or flimsy Python logic inside the agent itself.If we treat agents as autonomous employees, giving them root access and hoping they listen to instructions felt insane to me. I wanted a way to enforce hard constraints that the LLM cannot override, no matter how "jailbroken" it gets.So I built Cordum. It’s an open-source "Safety Kernel" that sits between the LLM's intent and the actual execution.The architecture is designed to be language-agnostic: 1. *Control Plane (Go/NATS/Redis):* Manages the state and policy. 2. *The Protocol (CAP v2):* A wire format that defines jobs, steps, and results. 3. *Workers:* You can write your agent in Python (using Pydantic), Node, or Go, and they all connect to the same safety mesh.Key features I focused on: - *The "Kill Switch":* Ability to revoke an agent's permissions instantly via the message bus, without killing the host server. - *Audit Logs:* Every intent and action is recorded (critical for when things go wrong). - *Policy Enforcement:* Blocking actions based on metadata (e.g., "Review required for any transfer > $50") before they reach the worker.It’s still early days (v0.x), but I’d love to hear your thoughts on the architecture. Is a separate control plane overkill, or is this where agentic infrastructure is heading?Repo: https://github.com/cordum-io/cordum Docs: [Link to your docs if you have them]Thanks!

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
AI-native
Project type
Commercial product
Normalized one-liner
security firewall for ai agents
Manually corrected
False

Could you build this?

No Building an external firewall/proxy for autonomous AI agents requires deep network security, protocol inspection, sandboxing, and runtime policy enforcement to prevent unauthorized actions and data leaks.

What it would actually take: The architecture requires an out-of-band or forward/reverse proxy (written in Rust or Go) intercepting tool execution requests, database queries, and network egress calls made by agent sandboxes. The hard parts include deterministic schema validation, zero-trust credential isolation, egress filtering to prevent SSRF and prompt injection data exfiltration, and low-latency interception. It requires specialized expertise in network security, container sandboxing, and systems engineering.

Discussion

7 comments analyzed.

Competitors mentioned: Exordex (AI agent testing/CI-CD tool), MCP security testing frameworks

Concerns raised: Latency impact when control plane intercepts every intent, Overkill for simple/demo use cases, Relying on prompt engineering for safety with production data

Feature requests: Chaos engineering features for agent testing, MCP security test integration

Competitors

Other products that read as similar to this one — 389 launches clear the similarity bar, closest 8 shown.

Attention rank: #271 of 390 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 79 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.