Stop your agents
from going rogue

Prismor gives enterprises a security control plane for AI agents. Full traceability of every tool call with security guardrails in production

Used by developers at
AmazonAdobeMicrosoftSalesforceVMwareOpenTableAmazonAdobeMicrosoftSalesforceVMwareOpenTable
Claude CodeCursorCodexCopilotLangGraphGitHubAWSAzureMCPSlackStripe
Claude Code

Opus 5

~/prismor-web

>Add a documentation page to the website
Reading the docs skill to understand requirements
Bash(cat skills/technical-docs-page/SKILL.md)
Loading doc structure, layout patterns, and component approach

Open source, independent layer to secure AI agents

PrismorDashboard/Overview
Overview
6 agentsToday
Tool calls, last 14 days
cloakedallowedblocked
1
3
5
7
9
11
13
Top tool calls
ToolAgentCalls
File readCursorcursor4
Package managerClaude AIclaude-code4
Slack MCP serverCursorcursor6
EnvironmentLangChainlangchain-api2
Network fetchCursorcursor2
Verdict distribution
14tool calls
allowed4
blocked8
cloaked2
Recent tool calls14 total
CallVerdict
Destructive actionlocal
claude-code · 4s ago
blocked
Credential readlocal
cursor · 11s ago
blocked
PrismorDashboard/Policies
Permission profiles
least privilege8 profiles
UserAgentStatus
Alice Chen
Claude AIclaude-code
Active
Sam Ortiz
Cursorcursor
Active
Maya Iyer
Cursorcursor
Scoped
Dan Brooks
Codexcodex
In review
Priya Nair
Windsurfwindsurf
Active
Tom Nakamura
GitHub Copilotcopilot
Active
Lena Fischer
LangChainlangchain-api
Scoped
Omar Haddad
Claude AIclaude-code
In review
PrismorDashboard/Audit log
Runtime monitor
intercepting10 events
Package install
allowed
Private key read
blocked
Model API key in environment
masked
Commit to feature branch
allowed
Dangerous command
blocked
Unrecognised outbound webhook
blocked
Dependency install
allowed
Secret exfiltration attempt
blocked
Push to protected branch
allowed
Live payment key
masked
Package install
allowed
Private key read
blocked
Model API key in environment
masked
Commit to feature branch
allowed
Dangerous command
blocked
Unrecognised outbound webhook
blocked
Dependency install
allowed
Secret exfiltration attempt
blocked
Push to protected branch
allowed
Live payment key
masked
Agent Security

An immune layer for every agent action

Your agents run hundreds of tool calls a session. Prismor catches each one before it executes, blocks the destructive ones, and strips secrets out before they reach the model. Every call lands in an audit trail you can read back later. Works with the OpenAI Agents SDK, MCP agents like Claude Code and Cursor, LangChain, and CrewAI

Every tool call intercepted, masked, and logged
Policy as Code

Security rules your whole team can version

Write your security rules once and apply them from the CLI. Set defaults for the org, override them per team, grant exemptions per person. You pull, lint, and apply the same way you ship infra config, and every change sits in git for review

Policies versioned, linted, and applied like infra
Full Visibility

Every agent action, on the record

Your agents run in the background. You see the output. Prismor captures what happened before it: every tool call at interception, what Prismor blocked, what it masked, who triggered the session. The full timeline is live in your dashboard while the agent is still running. Your security team can pull an export any time

Full session timeline, tool by tool

Secure by default Prismor plugs into existing workflows, enabling enterprises to get policy enforcement and a full audit trail on every agent action

Coverage across the categories we can test

Each bar is the percentage of adversarial security tests where the agent actually carried out the harmful action, tested live against production Claude and Codex agents. Lower is better. Prismor closes the gap in every category, both in the open-source policy engine and in the enterprise control plane. Hover any bar for the exact number.

Harmful outcome rate (%)0%25%50%75%100%ASI01Goal HijackASI02Tool MisuseASI03ID/Priv AbuseASI04Supply ChainASI05Code ExecutionASI06Memory Poisoning
Claude Opus 5
Codex (GPT-5.6)
Prismor (OSS)

Percentages come from a live benchmark against production Claude Opus 5 and Codex GPT-5.6 agents, with N=3–4 repeated attempts per test case, scored on a real side effect rather than model output. Prismor is the open-source policy engine, pooled across both agents. ASI01 is zero for every bar because no goal hijack attempt succeeded against either model. ASI06 reflects a Codex adapter gap that is already closed on Claude.

One security layer for every agent your team uses

Connect Prismor once and keep the same runtime policy, secret protection, and audit trail across coding agents, SDKs, and custom MCP workflows.

What developers are saying

Jorshin
Jorshin
@JustJorshin

Love the MCP gateway angle. One policy layer across everything is the right abstraction

liquidated0x
liquidated0x
@liquidated0x

bro this is actually clean, i've had claude code almost run rm -rf on my server once. policy checks would've saved me

Spekulator
Spekulator
@__spekulator__

the observe mode is the part i'd want tested: how often does it flag legitimate shell commands, and who maintains those policies when the repo changes?

YoooJJ
YoooJJ
@YoooJJ8cm

Honestly, AI trading bots need this more than humans

Duy Cao
Duy Cao
@duycao8655

gm, open source control plane that gates every tool call sounds like the missing guardrail. how heavy is the latency?

DeFi Tiger
DeFi Tiger
@defi_tigerr

enforce mode saves wallets tbh

Catman Yau
Catman Yau
@catmanyau

the enforce vs observe switch is smart! teams can see the blast radius before

Nine To Five Dude
Nine To Five Dude
@ninetofivedude

This is a real gap. The agent part gets all the attention, but visibility and control are what make it usable in production

Igor Fomich
Igor Fomich
@igorfomich

nice take on agent iam, the guardrail scoping feels solid. how do you handle secret rotation across delegated sub agents?

Zenchan
Zenchan
@zench4n

Local first security for agents is a strong direction. Secret redaction is table stakes, but policy enforcement around tool calls and package installs is where this gets really interesting

ApplyWise AI
ApplyWise AI
@ApplyWiseAi

this is genuinely needed. most agent stacks rn are a black box once you deploy them, and the "we'll add observability later" crowd finds out the hard way when something exfiltrates a token

Rohit YB
Rohit YB
@rohityb

Open source is the way to go! Superb demo and great product

Singhal
Singhal
@ai_singhal

super cool product!

Chevy
Chevy
@cchevyyc

so cool!

Rohit
Rohit
@rohityb

Tried it for 3 of my repositories. Super awesome man!

Oranah
Oranah
@oranahh

This is awesomeee

T Sintarhs
T Sintarhs
@tsintarhs

This is spot on. Most devs know security matters, it just never feels urgent enough. Auto PRs feel like the right approach.

Zack Korman
Zack Korman
@ZackKorman

I think this is a very solid approach

Natalie Levi
Natalie Levi
@NatalieLeviii

too good

Schelsk Dev Co
Schelsk Dev Co
@schelskedevco

interesting tool, does it run across all commit history, or just latest commit?

Ashutos
Ashutos
@withashutos

Just checked out @prismor_dev, This is actually sick. Prismor scans your GitHub repo, finds security issues, and just… opens a PR. Kudos to the team, love the idea for solving a real pain point without overcomplicating it. 🚀

Kshitiz Loharuka
Kshitiz Loharuka
@KshitizLoharuka

Hats off for providing us with this!!

mmmutantQ
mmmutantQ
@mmmutantQ

security is key especially as models become increasingly capable!

Ayush Rijith
Ayush Rijith
@AyushRijith

I was seeing openclaw and its cousins everywhere didn't know they had so many vulnerabilities. As prismor is free I'll try it and maybe post my feelings.

Rahul Kr Mall
Rahul Kr Mall
@Rahul_Kr_Mall

Oh thanks, I will check for those issues🫡🫶

SHello
SHello
@SHello97685

As enterprises are adapting agents into their workforce, security becomes very crucial part of the workflow. Looking forward for great work

Derek Nwachi
Derek Nwachi
@DerekNwachi

@prismor_dev is a standout. ​It's a "Security and Compliance Autopilot" that helps you ship faster with fewer bugs. You just connect it to your GitHub and let it work

Ogayanfe
Ogayanfe
@ogayanfe

@prismor_dev built a tool to help team catch security issues in your code by scanning your repo directly. You should check it out. It could really help you save time and a lot of money.

From agent chaos to auditable control

1

Connect

Wrap your agent framework with Prismor in one step. MCP, the OpenAI Agents SDK, LangChain, CrewAI. Your existing agents keep working.

2

Intercept

Every tool call routes through Prismor before it executes. The agent has no path around it.

3

Enforce

Your active policy decides each call: allow, block, or mask. Secrets never reach the model. Destructive commands never run.

4

Audit

Read the full timeline of every agent action in the dashboard: arguments, outcome, user, session. Export it when compliance asks.

5

Improve

Update policies from the CLI as your conventions change. Every rule is versioned and reviewed by a teammate, same as infra config.

Things people ask.