Agent boundary review

One question, asked about your product: where does the thing that enforces the boundary take its parameters from?

Every serious AI-agent escape of 2026 had the same shape — the agent trusted something the repository supplied. The component enforcing the boundary runs in the environment it polices, and reads its parameters from untrusted input: a repository, an issue, a patch, a tool result. That makes these boundaries testable, and I have tested them on fourteen products.

What the review covers

What you get

Formats

Scope-dependent pricing; a short call first is free and I can usually tell you in twenty minutes whether your git path is one of the known gaps.

What I don't do

One scope, done properly, beats a list of services. If your problem is outside it, I will say so in the first call.

Contact

Open an issue on either repo, or reach out directly. Findings I come across are reported privately to the vendor first and published only after they respond — that applies to reviews too.