{"data":{"slug":"atrayee-dev-secure-ai-agent-boundary","name":"secure-ai-agent-boundary","tagline":"Secure AI Engineering Framework 2026: Data-Boundary Security for Frontier Models","github_url":"https://github.com/Atrayee-dev/secure-ai-agent-boundary","owner":"Atrayee-dev","repo":"secure-ai-agent-boundary","owner_avatar_url":"https://avatars.githubusercontent.com/u/191036427?v=4","primary_language":"HTML","stars":115,"forks":0,"topics":["ai-security","claude-opus","coding-agents","data-boundary","government-tech","gpt-5-5","local-llm","mirogate","secure-ai","secure-coding"],"archived":false,"github_pushed_at":"2026-09-20T00:45:40+00:00","maintenance_label":"Very active","stars_delta_30d":-36,"url":"https://www.graphcanon.com/tools/atrayee-dev-secure-ai-agent-boundary","markdown_url":"https://www.graphcanon.com/tools/atrayee-dev-secure-ai-agent-boundary.md","api_url":"https://www.graphcanon.com/api/graphcanon/tools/atrayee-dev-secure-ai-agent-boundary","graph_url":"https://www.graphcanon.com/api/graphcanon/graph?tool=atrayee-dev-secure-ai-agent-boundary","description":"Secure AI Engineering Framework 2026: Data-Boundary Security for Frontier Models","homepage_url":null,"license":null,"open_issues":0,"watchers":0,"ai_summary":"Provides a decoupled configuration layer that manages data security and model access control within an existing Git workflow.","readme_excerpt":"## 📖 Getting Started (Configuration Philosophy)\n\nCodeBoundary does not require installing a daemon, patching your kernel, or running a heavyweight control plane. It is designed as a **decoupled configuration layer** that overlays your existing Git workflow.\n\nThe primary entry point is a file called `.codeboundary.yml` at the root of your repository. This file defines:\n\n1. The **default contract** for your project (applied to all model sessions unless overridden).\n2. A list of **allowed models** (by name and fingerprint).\n3. The **audit log destination** (local `.cb-audit/` directory, or forwarded to an internal log aggregator).\n\nFrom there, individual developers can define **session contracts** in their local working directory. These session contracts extend or restrict the default contract for specific tasks.\n\nCodeBoundary is editor-agnostic. It integrates with any tool that can execute a CLI command before and after an edit, or any IDE extension that supports LSP-like hook callbacks.\n\n---\n\n---\n\n## 📄 License\n\nThis project is released under the **MIT License**. You are free to use, modify, distribute, and incorporate CodeBoundary into internal or commercial products, provided that the original copyright notice and this permission notice appear in all copies or substantial portions of the software.\n\nSee the full license text at: [https://opensource.org/licenses/MIT](https://opensource.org/licenses/MIT)\n\n---\n\n*CodeBoundary — Engineering with boundaries, not blind trust. © 2026*","github_created_at":"2026-06-28T20:50:20+00:00","created_at":"2026-07-15T11:01:34.180592+00:00","updated_at":"2026-09-20T05:08:05.048544+00:00","categories":[{"slug":"ai-agents","name":"AI Agents","url":"https://www.graphcanon.com/categories/ai-agents","markdown_url":"https://www.graphcanon.com/categories/ai-agents.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/ai-agents"},{"slug":"developer-tools","name":"Developer Tools","url":"https://www.graphcanon.com/categories/developer-tools","markdown_url":"https://www.graphcanon.com/categories/developer-tools.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/developer-tools"},{"slug":"evaluation-observability","name":"Evaluation & Observability","url":"https://www.graphcanon.com/categories/evaluation-observability","markdown_url":"https://www.graphcanon.com/categories/evaluation-observability.md","api_url":"https://www.graphcanon.com/api/graphcanon/categories/evaluation-observability"}],"tags":[{"slug":"ai-security","name":"ai-security"},{"slug":"claude-opus","name":"claude-opus"},{"slug":"coding-agents","name":"coding-agents"},{"slug":"data-boundary","name":"data-boundary"},{"slug":"government-tech","name":"government-tech"},{"slug":"gpt-5-5","name":"gpt-5-5"},{"slug":"local-llm","name":"local-llm"},{"slug":"mirogate","name":"mirogate"}],"trust":{"provenance":{"is_fork":false,"github_id":1283354276,"owner_type":"User","methodology":"github_public_v1","parent_repo":null,"near_duplicate_slugs":[]},"computed_at":"2026-09-20T05:08:02.933Z","maintenance":{"label":"Very active","score":96,"methodology":"github_public_v1","releases_90d":0,"days_since_push":0,"last_release_at":null,"stars_delta_30d":-36,"open_issues_delta_30d":0},"security_summary":{"status":"no_lockfile","scanner":null,"low_count":0,"high_count":0,"last_scan_at":"2026-07-15T11:01:35.522Z","medium_count":0,"scan_profile":"none","critical_count":0}},"capability_facts":{"scan":{"source":"repo_scan","observed_at":"2026-09-20T05:08:03.981Z"},"languages":{"value":["html"],"source":"github.language","observed_at":"2026-09-20T05:08:03.981Z"}},"decision_facts":{"hosting":null,"pricing":null,"requirements":{"notes":["Secure AI Agent Boundary does not require a daemon, kernel patching, or heavyweight control plane operation."]},"constraints":null,"when_to_use":["Use secure-ai-agent-boundary when you need to enforce strict model access controls within a git-based workflow without overhauling your infrastructure.","It is suitable for organizations that require session-specific security settings directly from developers' local working directories, within an MIT License-compliant framework."],"when_not_to_use":["Avoid secure-ai-agent-boundary if you have limited bandwidth for integrating new tools and cannot allocate resources to learn a new configuration layer.","Do not use it when your project strictly needs real-time model access controls enforced via a heavyweight control-plane method, as this tool relies on decoupled configurations."],"source":"enrich:decision_facts","observed_at":"2026-07-17T07:07:00.948Z"},"constraint_facets":null,"decision_summary":[{"label":"Requirements","value":"Secure AI Agent Boundary does not require a daemon, kernel patching, or heavyweight control plane operation."},{"label":"Adopt for","value":"secure-ai-agent-boundary provides decoupled configuration management for data security and model access control, overlaying existing Git workflows with minimal overhead."},{"label":"License detail","value":"MIT License allows free usage and distribution as long as the original copyright notice and license terms are preserved in copies or substantial portions of the software."}]}}