Cordon is the action firewall for AI agents. Every proposed action — shell commands, file writes, tool calls — runs through a suite of deterministic probes that return an allow / flag / block verdict in under a millisecond. No LLM judge. No latency tax. No false positives.
pip install cordon-ai && cordon benchmark --profile strict
Type a shell command (or pick a preset) and watch Cordon decide.
The check runs server-side using the exact same probes that ship
in pip install cordon-ai.
This widget only exercises the shell-command probes. The SDK also
inspects file writes — typosquatted packages, leaked secrets,
exfiltration in artifacts, silent failures, test suppression —
which are the attacks LLM agents actually attempt. Run
cordon benchmark to see the full 42-task suite.
Every other safety layer is reactive or non-deterministic. Cordon is the only one that's both: deterministic and ahead of the action.
pip install reqeusts looks fine to an LLM
reading the agent's narration. A Levenshtein check against
the top 200 PyPI names catches it deterministically.
An LLM judge adds ~1 second per agent step and ~$3,500/year per million steps. Cordon adds 0.2 ms and $0. It's also deterministic — same verdict every time.
Substring block-lists block rm -rf ./build and
miss :(){ :|:& };:. Cordon's seven semantic
probes target the action structure, not the surface text.
# In your agent from cordon import Guard, Action guard = Guard.strict() def run_shell(cmd: str) -> str: verdict = guard.check(Action(kind="shell", command=cmd)) if verdict.blocked: raise PermissionError(verdict.summary) return subprocess.check_output(cmd, shell=True)