Security Firewall for Agents — Ryan Dahl, Deno
Ryan Dahl from Deno presents Claw Patrol, a security system for AI agents that have access to sensitive production environments like databases and AWS.
The problem is that agents can fall victim to prompt injection—malicious instructions smuggled in through support channels connected to the agent. Although modern AI models like Opus often refuse harmful commands, they cannot be reliably counted on to resist all possible attacks. The solution is Claw Patrol, a proxy that sits between the agent and the resource and inspects every byte of data leaving the agent—even at the protocol level below HTTP, since agents can open direct database connections that no HTTP rule would catch. Rules are written in HCL (Terraform's configuration language), stored in git, and can be tested against fake requests. The proxy can also forward decisions to an AI judge or a human in Slack before anything is allowed to run.
Vibekollen prepared this summary with AI from the original publication. The content belongs to AI Engineer.