(no title)
ryanrasti | 20 days ago
The fix: if agent reads sensitive data, it structurally can't send to unauthorized sinks -- even if both actions are permitted individually. Building this now with object-capabilities + IFC (https://exoagent.io)
Curious what blockers you've hit -- this is exactly the problem space I'm in.
No comments yet.