2026-06 – 2026-06 · repo

CORDON

A containment layer for AI agent swarms

1st place — AGI House — Agent Identity Build Day (37 teams)

An agent containment prototype with provenance taint, a credential broker, contact tracing and signed audit records. Its recorded evaluation uses handcrafted attacks and benign controls, rather than production traffic.

Limit what an exposed agent can do

An agent can encounter hostile instructions while reading a document or receiving a handoff. CORDON explores how an agent runtime can restrict sensitive actions after that exposure, while retaining useful work by other agents.

Assume the injection lands

The runtime records provenance taint when an agent reads an untrusted channel. Credential requests pass through a broker that checks this state before calling its secret resolver. The recorded fixture reported . That observation is scoped to those controlled tests; the threat model still depends on instrumented tool calls and handoffs.

Tracing the outbreak

The reference monitor follows the recorded delegation graph to identify exposed agents and request their quarantine. Decisions are written to an Ed25519-signed, hash-chained audit log for replay. Agent taint and broker controls are separate from hardware isolation; the sandbox setup does not establish that boundary.

What the evaluation shows

against for the keyword baseline, while preserving of benign work. The number worth stating plainly is the other one: .

The evaluation is : ten handcrafted attacks and seven benign controls. One benign request was denied. These results describe this fixture and baseline, not universal prompt-injection protection. The default demo is scripted; live integrations require provider credentials. No current remote-service availability or new evaluation was established by this update.

How it was built

Time:
About two days, solo — roughly six hours of preparation and a twelve-hour build day.
Tools:
Claude Code
Mine:
The threat model, the decision to contain rather than detect, the 14-type event contract frozen as the first commit, the phase gates and their exit tests, and the choice to disclose the false positive instead of tuning it out.
How "not broken" was decided:
22 automated tests; 20 run offline in 0.34s, two need live credentials.