Observed Signal · Sep 9, 2026 · Technical Release · Source: DEV Community · Impact: 1/5 · Sentiment: Neutral
Architecture Pattern: Splitting AI Agent Planner and Runner for Secure SSH
This article discusses a security architecture pattern for AI agents that operate on remote servers via SSH. It advocates for splitting the agent into three distinct processes: a planner that interprets user prompts and generates a patch, a gate that validates the patch against a strict contract, and a runner that applies the approved patch to the host. This separation prevents the model from directly accessing sensitive credentials or executing arbitrary commands. The pattern emphasizes the definition of a clear trust boundary, the use of a job file with a digest, and strict path and command allowlisting. The article includes a code example for a gate and runner in Python, and stresses the importance of boring, predictable code in the runner to limit blast radius.
The article provides a niche technical architecture pattern for AI agent security, relevant to AI in AdTech but lacks a specific industry event or broad impact.
Track Real-Time AI Agent Security Signals & Market Shifts
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- The article proposes a three-process architecture (planner, gate, runner) to separate AI model interaction from system execution.
- The gate validates patches against a contract file (contract.json) with allowed paths, commands, and size limits.
- The runner only applies an approved job file and cannot communicate with the model or open a shell.
- The article provides a Python code example for the gate and runner.
- The article is part of MonkeyCode's product outreach, offering free model access and server options.
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Defense Architecture for AI Agents Against Prompt Attacks
An open-source, four-layer defense-in-depth framework is presented to secure autonomous AI agents and LLM deployments against prompt injection, tool-poisoning, and escape/fugitivity. The design groups sensors and controls across: (1) input sanitization (text and visual), (2) gateway and sandboxing with policy enforcement, (3) runtime monitoring for each tool call, and (4) tool/data supply-chain protections for MCP servers. The framework lists named components (e.g., hermes-shield, vision-injection-guard, ai-guard-gateway, seblight, agent-shield-runtime, mcp-schema-sentinel) and includes post-hoc confidence validation using conformal prediction techniques. The codebase and architecture are available on GitHub and optimized for CPU-only local deployment under permissive/open licenses.
Sandboxing AI Agents: Tool Guards and Credential Boundaries
A Senior Software Engineer describes production practices for securing conversational AI agents built with Spring Boot and Spring AI. The article covers four defenses: wrapping tool callbacks with a guard that enforces policy, treating tool output as data (not instructions) with prompt and eval safeguards, redacting and preventing secrets from appearing in agent traces after a paper showed chain-of-thought leaks, and using least-privilege credentials as the agent's sandbox boundary. The author contrasts microVM sandboxes (Docker Sandboxes) for coding agents with policy-and-credential-based cages for backend tool-calling agents and provides a checklist and test-driven approach to enforce the guard and tenant isolation.
Practical Guardrails for AI Agents
A developer-published guide details a four-layer set of guardrails to safely run agentic AI tools that can touch files, terminals, or databases. The layers are: (1) agent and editor controls (default read-only/ask mode, allowlist/denylist for commands, scoped workspace, per-chat resets), (2) repository protections (protect main branch, require review and CI, allow commits but not pushes, secret-scanning hooks), (3) data and credentials (provide read-only roles, no production write access, keep secrets out of prompts), and (4) a human-in-the-loop gate for irreversible actions (schema migrations, deletes, deploys, force-pushes, financial actions or messages to real users). The author argues these guardrails preserve developer speed while eliminating paths to unrecoverable damage. Publication date: 2026-06-01.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
