{"repo":"coproduct-opensource/nucleus","free":true,"listed":false,"github":"https://github.com/coproduct-opensource/nucleus","clone":"git clone https://github.com/coproduct-opensource/nucleus.git","description":"Enforced permissions for AI agents - policy + enforcement in one stack","language":"Rust","stars":20,"topics":["agent-security","ai-security","formal-verification","github-actions","lattice","mcp-security","rust","security-scanner"],"license":"MIT","category":"ai-agents","readme_excerpt":"Nucleus Don't trust the agent. Verify it. Signed identity, declared guarantees, receipts anyone can check. Nucleus is a vendor-agnostic secure runtime for AI agents: it enforces what an agent may do, proves the enforcement boundary is sound, attests how every result was produced, and federates identity and trust — without a single long-lived secret. Assume the agent is compromised. Constrain what it can do anyway. Prove the constraints hold. At its core is a small, dependency-free information-flow algebra. Two primitives — join and flows to — enforce information-flow control under four algebraic laws. Once untrusted web content enters a session through a mediated ingest channel , it cannot silently reach a privileged sink like git push . That property is machine-checked, not hoped. The qualifier is load-bearing, so it is stated here rather than in a footnote: the guarantee covers content the runtime observes . Fetches through web fetch / web search , file reads, and memory recalls are observed. Bytes an agent obtains by running a command — curl inside run — are observed only when NUCLEUS PARANOID TOOL IO=1 , because the runtime cannot tell curl from ls in a command's output and tainting all of it makes a session \"one privileged action then locked\". That is an operator's policy call, and until it is made, command output is an unmediated ingest channel. This is the lethal trifecta — private data + untrusted content + an exfiltration sink — made safe by non-interference : attack","default_branch":null,"files":null,"tree":[],"storefront":"/r/coproduct-opensource","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/coproduct-opensource/nucleus/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}