Protection against AI-agent attacks

Stop AI agents before they do harm.

Araphor contains AI agents and protects the systems they reach by stopping forbidden actions before they take effect.

Start in Observe. Araphor suggests policy from real activity. You approve it before Protect is enabled.

ARAPHOR / WORKLOAD PROTECTIONOBSERVE Araphor console with observed workloads and suggested protection policies POLICY READYReview suggested controls before enforcement
Observe
See actions without blocking
Suggest
Build policy from real activity
Approve
You decide what is allowed
Protect
Stop forbidden actions

A real agent intrusion · Hugging Face, 2026

One intrusion.
Many places to stop it.

Follow the published attack path. Switch on Araphor to see where the attack stops.

Published incidentWith Araphor

The agent keeps trying. The boundary keeps holding.

worker-aproduction dataset worker

PUBLISHED INCIDENT

ARAPHOR · PROTECT MODE

INPUT

Dataset input accepted

14 valid HF credentials OBSERVED

PROCESS

Conversion worker active

worker-a ACTIVE

FILE

Protected file open requested

/proc/self/environ EFFECT REQUESTED

FILE

Request allowed

FILE · SUCCEEDED CONTINUED

EFFECT

Secrets returned as rows

HARM CONFIRMED COMPLETED

FOLLOW-ON

Agent continues the intrusion

17,600 recovered actions INTRUSION CONTINUED

FILE POLICY

Policy denies file open

FILE · DENIED PREVENTED

EVIDENCE

Secret remains unread

0 bytes · worker healthy NO EFFECT
DECISION TRACE · HF-009 PUBLISHED PATH
  1. REQUEST/proc/self/environ
  2. DECISIONFILE · SUCCEEDED
  3. EFFECTSecrets returned as rows
  4. FOLLOW-ONAgent continues the intrusion
  5. RECORDED17,600 recovered actions

This replay follows the published Hugging Face timeline. The protected path first stops the HDF5 request for /proc/self/environ.

OpenAI incident report Hugging Face technical timeline

Product

Observe. Approve.
Protect.

Araphor records actions from agents and workloads, suggests policy, and enforces only what you approve.

Araphor console showing protected and observed Kubernetes workloads, suggested controls, evidence coverage, and open findings
Build policy from real activity See which files, processes, connections, and Kubernetes actions are used. Approve the policy before enforcement.

Available for selected Linux and Kubernetes environments.

What Araphor stops

Protect the action.
Not the promise.

Prompts guide the agent. Araphor controls what it can do to the system.

01FILE

Keep secrets unread

Deny access to credentials and protected files before bytes return.

02PROCESS

Stop a new shell

Deny an unapproved executable before the new process starts.

03NETWORK

Close forbidden routes

Deny connections to protected destinations before the workload reaches them.

04KUBERNETES

Reject dangerous workloads

Reject privileged and disallowed Kubernetes changes before the API stores them.

Why Araphor

Hold the line.
Before harm crosses it.

01

Named for a defender

In Tolkien's histories, Araphor drove an invading force back from Fornost and the North Downs.

02

Built to hold the boundary

Araphor holds the execution boundary around an agent or workload. Forbidden actions do not cross it.

THE BOUNDARY STILL HOLDS WHEN

  • the agent changes its tool or tactic;
  • a prompt or tool guardrail is bypassed;
  • a compromised service carries out the action; or
  • no human reviews the next action.

Why this matters now

17,600

agent actions reconstructed across the 4.5-day Hugging Face campaign

The agent kept trying.
One path was enough.

AI agents can change tactics and try again. They need one allowed path. Araphor checks each covered action at the execution boundary and stops what policy forbids.

CONFIRMED INTRUSION · 2026

Hugging Face

An OpenAI evaluation agent escaped its sandbox, compromised a worker, read secrets, reached cloud metadata, and moved through Kubernetes.

Technical timeline

THREE CONFIRMED INTRUSIONS · 2026

Anthropic evaluations

Anthropic found three incidents where Claude models reached the open internet from evaluation environments and gained unauthorized access to three organizations' systems.

Anthropic investigation

CONFIRMED LIVE-INTERNET ACTIONS · 2026

UK AI Security Institute

In 10 evaluation runs, agents took 19 unsanctioned actions against real people and organizations. A human stopped the most serious attempt, and no resulting harm was found.

AISI incident report

CONFIRMED DATA DELETION · 2025

Replit

Replit confirmed that its Agent deleted data from an app database. A rollback restored the data after the harmful action had happened.

Replit disclosure

PATCHED CVE · 2025

GitHub Copilot

A prompt injection could change VS Code settings, remove command approvals, and make the agent run terminal commands.

CVE-2025-53773 research

REPRODUCED ATTACK · 2025

MCP tool poisoning

Hidden tool instructions made an agent read configuration and SSH-key files and send the contents to a malicious server.

Invariant Labs research
What the agent tried Where Araphor stops it Protected result
Read /proc/self/environ Deny the file open before bytes return SECRET UNREAD
Start shell tools from the worker Deny the process execution before start NO PROCESS
Connect to cloud metadata Deny the connection before credentials return NO CREDENTIAL
Create a privileged Pod Reject the Pod before Kubernetes stores it NO NODE ROOT

How Araphor works

Observe. Review.
Then enforce.

Araphor enforces policy around the agent or workload you protect. No application, agent, or model change is required.

  1. 01

    Record actions

    See the files, processes, connections, tools, and Kubernetes actions in use.

    OBSERVE
  2. 02

    Review suggested policy

    Araphor suggests controls from real activity. You decide what becomes policy.

    SUGGEST
  3. 03

    Enable Protect

    Araphor applies the approved policy to the selected agent or workload.

    PROTECT
  4. 04

    Verify the result

    The event record shows the request, the decision, and the resulting system effect.

    PROVE

Where Araphor fits

Protect the agent.
Protect the workload.

Deploy Araphor where AI-agent actions begin, where they take effect, or both.

01

Evaluation and training agents

Keep experimental agents and sandboxes inside their approved boundaries.

02

Coding and operations agents

Control file, process, network, browser, and tool actions from agents with real access.

03

AI-platform workloads

Protect dataset, evaluation, inference, and automation workers from agent-driven attacks.

04

Kubernetes platforms

Stop secret access, dangerous workloads, protected connections, and privilege escalation.

Questions

What teams ask.

Why call it Araphor?

Araphor defended Fornost when an invading force tried to break through. The product holds the execution boundary before a harmful action reaches the system.

Is Araphor an AI guardrail?

No. Guardrails influence what an agent decides. Araphor enforces policy on the resulting action.

Does Araphor need to see the agent?

No. Araphor can protect a workload by enforcing policy on its local actions. When deployed around an agent, it can also use task and approval context to contain the agent.

Must Araphor recognize the model?

No. The policy applies to the action, regardless of which model or software requested it.

Does Araphor replace other security tools?

No. Keep your identity, endpoint, detection, and incident-response controls. Araphor adds prevention at the point of action.

Early access

Start with one
agent or workload.

Begin in Observe. Review the suggested policy with us. Turn on Protect when ready.

Product updates are included. Unsubscribe at any time.

Prefer a walkthrough?

See Observe → Suggest → Protect on a real agent or workload in 30 minutes.
Book a 30-minute demo