AI/ML • 2026

CORDON

Containment for AI agent swarms: track untrusted input and agent contact, deny protected credentials, and quarantine the affected part of the swarm.

CORDON — Agent containment. Conceptual illustration of a reference-monitor boundary, quarantined amber agents, a protected credential vault and audit records.
AI-generated conceptual illustration.

Problem

An injected instruction can spread through agent handoffs. Content detection alone cannot establish which agents should retain access to sensitive tools and credentials.

Approach

Routed tool calls and handoffs through a Python reference monitor, combining provenance taint, contact tracing and a credential broker that denies access before resolving a secret. A signed audit trail and React dashboard make containment decisions inspectable and replayable.

Impact

Won first place at AGI House’s Agent Identity Build Day, with 37 teams confirmed by the user. Recorded tests stopped all 10 handcrafted injections and preserved six of seven benign cases; the keyword baseline stopped four injections and preserved three benign cases. This is a bounded synthetic evaluation.

Key Metrics

10 of 10
Recorded handcrafted injections stopped
6 of 7
Recorded benign cases preserved
1st · 37 teams
User-confirmed event result

Technologies

PythonFastAPIOpenAI Agents SDKReactReact FlowSSEEd25519

Links

My Role

Developed the containment design, tool boundary, dashboard and evaluation with AI-assisted implementation. The default demonstration is scripted; live provider integrations require valid credentials.

Team Size: 1 person