Block the trifecta at the tool boundary
Cerberus correlates sensitive data access, untrusted content and outbound intent across the session, and holds the guarded call when they close.
Solution
The attack needs no zero-day and no malware — three tool calls the agent was designed to make, and an instruction hidden in content it was told to read. Defending it means judging the action, not the text.
Most security controls quietly assume a person reviews the consequential action. An agent does not wait, and the exfiltration looks exactly like the work it was asked to do.
Cerberus correlates sensitive data access, untrusted content and outbound intent across the session, and holds the guarded call when they close.
Argus red-teams autonomous systems the way an adversary would, so exposure is found by you and not disclosed to you.
Mimir seeds decoys that reveal when an agent's memory has been tampered with. It is in preview and labeled as such.
Each decision carries the signals and contamination graph that produced it, so an incident review is a query rather than an excavation.
Start with the MIT-licensed Cerberus core in your own environment; the rest layers on top.
Warden · By Odingard
Warden stands the runtime up alongside your team, reviews the boundaries you are enforcing, and red-teams the agents behind them.
The core is MIT licensed and installs in your own environment. The evidence set behind it is published in full.