Never trust, always verify. Even your own agents.
Every agent, skill and MCP server you install is a stranger's code running as you. This inspects it before it lands, contains it while it runs, and gives you one clear answer.
Agents and skills spread like npm packages or browser extensions. Most are fine. The dangerous ones look identical — until they're already running with your keys.
A single markdown file or setup.sh can read your SSH keys, dump your environment to a webhook, or pipe a remote script straight into your shell.
Hidden instructions in tool descriptions. Zero-width characters your eyes can't see. Text that tells your agent to leak secrets and stay quiet about it.
→ prompt injection · tool poisoning · hidden unicodeThe rug pull: an artifact you approved that mutates in a later update.
No one reviews every line of every add-on. So the risky ones just walk in.
Shell access, your credentials, your files. Trust it and you trust its author.
This is a real scan report, replayed. Nothing is uploaded and nothing is executed — the scanner only ever reads.
The same model enterprise security runs on — applied to the AI agents you install and the ones you ship. Three principles, enforced by four layers.
Every artifact is read before it runs, its provenance weighed, and unsigned or unknown sources are held to a stricter bar automatically. Nothing is trusted just because it's popular or already installed.
→ layers 01 Static · 02 Stateful · 03 Provenance Honest scope: by default we detect that a signature exists (tier Declared). Cryptographic verification (tier Verified) is opt-in via--verify-signatures with cosign.
Default-deny egress, wildcard-permission (tools: *) detection, and per-tool scope keep an agent to exactly the reach its job requires — and nothing more.
The runtime layer trusts the code with nothing: a kernel-level network jail and live MCP inspection contain a payload that slips past the static tiers, so one bad artifact can't reach your keys or the network.
→ layer 04 Runtime ·afw run --isolate
Honest scope: the bypass-proof jail needs Linux with unshare privileges. Without them it falls back to a proxy-level allowlist — weaker, and stated as such.
Read the code, manifests and model-facing text before anything runs.
afw scanPin what you approved, then catch the update that silently changes it.
afw pinUnsigned and unknown sources are held to a stricter bar automatically.
--verify-signaturesDefault-deny egress, live MCP inspection, kernel-level network jail.
afw run --isolateThis page is the 30-second version. Stop here, or keep going.
No account. No API key. No telemetry. It runs entirely on your machine.