IK ENGINEERING EVIDENCEPublic AWS demonstration

AGENTIC AI SECURITY · SDLC

A patch can be proposed.
Permission must be earned.

Inspect a disposable repository, review a proposed fix, and decide whether it may execute. Test the same boundary with an injected tool request or a patch changed after approval.

Inspect→Plan→Guardrails AI→Human approval→Executor + tests

Review workspace

Ready

The fixture computes tax only. The requirement is subtotal plus 10% tax.

The page loads independently of the validator. A first security check after inactivity may take up to 30 seconds to initialize; no write is permitted during initialization.

Sanitized execution trace

0 patch writes

Decisions come from the server. Every repository action crosses the Guardrails AI validator. Approval is enforced again by the executor.

ActionDecisionReason
Choose a scenario and inspect the repository.

Preparing validator…

What the evidence establishes

Loading measured evaluation…

GitHub delivery and live-model evaluation

Loading GitHub evidence…

Loading live-model results…

Scope a client can verify

LangGraph orchestrates inspection, planning and validation. A custom Guardrails AI validator enforces a narrow tool and source policy. The executor binds review to a patch digest, atomically consumes approval in DynamoDB, then writes an isolated fixture and evaluates its arithmetic. The public sandbox creates an inspectable patch artifact. A separate GitHub Actions bot proposes that same validated change in a real sandbox PR, with checks on its exact commit and human review required before merge.

Normal planning replays a recorded model proposal when available; the attack scenario deliberately injects a forbidden tool proposal at the boundary. The sandbox supports one arithmetic file, not general repository editing. Public reviewer identity is a browser session; a production integration needs enterprise SSO, separated reviewer roles, a general sandbox and client-specific Git/CI adapters. The GitHub sandbox workflow is separate from this same-browser interactive approval exercise. These tests measure the bounded implementation, not universal prompt-injection resistance.