Untrusted content enters
A README, issue, webpage, email, or tool result enters the agent workspace with provenance attached.
TRUST THE AGENT.
VERIFY THE ACTION.
Atreides is an MCP security gateway that blocks unsafe agent tool calls before execution, independent of the LLM's own reasoning, then emits a verifiable receipt explaining exactly why.
01 / ATTACK REPLAY
Judges can see the complete before/after: an indirect prompt injection attempts secret egress, Atreides blocks the unauthorized MCP action, and the receipt proves why.
01 / EXTERNAL ISSUE
Tracing capability and provenance before execution.
The same indirect instruction reaches a privileged action with no policy boundary.
No LLM classification can stop a tool call by itself.The exact action is evaluated before the MCP boundary.
Deterministic policy checks provenance, sensitivity, destination, and impact.The decision reason and receipt hash are retained for review.
Cryptographic evidence, not a model confidence score.The baseline is deliberately synthetic. The block and receipt are real gateway results.
Each frame is an auditable transition, not a model guess.
02 / THE DIFFERENCE
Detection asks whether a phrase looks dangerous. Atreides asks whether untrusted context is authorized to use a risky MCP capability, then enforces that answer outside the model.
01Policy is deterministic.
02Evidence is portable.
03Enforcement is upstream-aware.
03 / WORKFLOW
This is the complete control path. The model may still see the malicious instruction, but Atreides governs the tool boundary before anything leaves.
A README, issue, webpage, email, or tool result enters the agent workspace with provenance attached.
Click any step to scrub the workflow. Autoplay pauses for reduced-motion users.
04 / POLICY LAB
This is not a mock. Configure an action and evaluate it against the live versioned policy gateway. Every result becomes a trust receipt.
LIVE POLICY RESULT
readyConfigure an action to inspect its authorization path.Atreides evaluates provenance, sensitivity, destination, and impact before execution.
05 / OPERATOR CONSOLE
The before/after proof produces a real policy receipt. Inspect its rule, version, integrity state, and hash here.
Run the proof ↑