Security
Assume the agent is fooled. Then decide, in the kernel, what it can reach.
An AI agent will be talked into something sooner or later. Harobanda does not bet on catching every bad sentence. It decides, before the agent starts, what the agent's program can reach — and the kernel, the core of the operating system, holds it there whatever the agent is told. These four pages show what that covers today, where you can see each part for yourself, and what it does not do yet.
What changed
An agent reads its orders and its data through the same door.
Ordinary security keeps code and data apart: a database query built with parameters cannot turn into a command. A language model has no such line. Everything it reads — a document, a web page, an email, the answer of a tool — it may take as an instruction, and an agent reads the open world while holding tools, passwords and a network. The attack is now a sentence, and a sentence costs nothing to try again.
Most of the field answers by trying to recognise the bad sentence before it acts. That helps, and it is a matter of odds: the attacker gets a new try with every document the agent reads. Harobanda starts from the other end. It assumes the model will be fooled, and fixes in advance how much a fooled model can do.
Harobanda never stops a model from being fooled. It decides the size of what a fooled model can do.
Who holds what
The software above asks who asked. The kernel asks how far.
Software above the machine can decide who may act: which program may change something real, and which may only propose. That rule lives inside a program, and a program can be wrong. Harobanda adds a second line underneath it. The kernel does not read prompts. It answers a program's requests — open this file, connect there, start that — and the answers were fixed from the program's file before the program started. A sentence in the model's context cannot move them.
The file declares
Every program the machine runs is a few lines in one text file: what it needs, which disks it sees, which user it runs as, how much memory and processor it may use — and, for each, why. harb check refuses the file if a program needs what nobody granted.
The kernel refuses
A program that did not ask for the network gets an empty one. The disks it did not name are not in its view. It cannot start another program unless its file says so, and 25 calls that would change the machine itself are refused to every program. The rule is set before the program runs, and the program cannot lift it.
The record keeps
A machine that keeps a record signs one line for every boot with its own key: which file it ran, and whether the boot matched it. Anyone holding the public half can check that no line was changed, and the secret never leaves the device.
Said plainly
What the machine does not do yet.
- No route is not no way.
EGRESSwrites the routing table, so the machine knows no way out. A filter that also stops a program looking for one is not built. - Boots are signed; actions are not. The record says what the machine was and what it judged of itself. What an agent did inside its walls is that program's record to keep, and the two are not yet joined.
- No clock of its own. The record carries no time, because the board has none. A machine can ask an authority its fleet declares how late its record's last line can be, and keeps the signed answer beside the record; with no answer, the record stays ordered and undated, and the witness that reads it says so. That runs in the emulator. A board's real clock, and a time taken from the network instead of a clock, are not built.
- No board yet. Every boot these pages quote ran in an emulator. The watchdog's real restart and the board's own console are the two things only the first board can show.
- No fingerprint on a model. Nothing yet checks a model file, or a program placed in the image, against a fingerprint the way the kernel is checked.
- The walls are the kernel's. A flaw in the kernel is a flaw in them. It is Linux, kept as pinned source and built here — and it is still Linux.
- No private way yet to report a flaw. A security policy and a contact for it are the next thing to publish.
Next: What it refuses → A program asked from inside what it can reach, in the machine's own words, and the 25 calls no file can ask for.