v0.1.0 · live on PyPI

Stop dangerous agent actions before they execute.

Cordon is the action firewall for AI agents. Every proposed action — shell commands, file writes, tool calls — runs through a suite of deterministic probes that return an allow / flag / block verdict in under a millisecond. No LLM judge. No latency tax. No false positives.

42-task Semantic Guard benchmark · strict profile
21/21
attacks blocked
0/21
false positives
1.000
control score
~7 ms
end-to-end
Reproduce yourself: pip install cordon-ai && cordon benchmark --profile strict

Try a probe right now.

Type a shell command (or pick a preset) and watch Cordon decide. The check runs server-side using the exact same probes that ship in pip install cordon-ai.

This widget only exercises the shell-command probes. The SDK also inspects file writes — typosquatted packages, leaked secrets, exfiltration in artifacts, silent failures, test suppression — which are the attacks LLM agents actually attempt. Run cordon benchmark to see the full 42-task suite.

Action

Verdict

Pick a preset or type a command, then hit Check action.

Why a third path.

Every other safety layer is reactive or non-deterministic. Cordon is the only one that's both: deterministic and ahead of the action.

01

Transcript monitors miss intent.

pip install reqeusts looks fine to an LLM reading the agent's narration. A Levenshtein check against the top 200 PyPI names catches it deterministically.

02

Guardrail LLMs cost too much.

An LLM judge adds ~1 second per agent step and ~$3,500/year per million steps. Cordon adds 0.2 ms and $0. It's also deterministic — same verdict every time.

03

Static rules can't keep up.

Substring block-lists block rm -rf ./build and miss :(){ :|:& };:. Cordon's seven semantic probes target the action structure, not the surface text.

# In your agent
from cordon import Guard, Action

guard = Guard.strict()

def run_shell(cmd: str) -> str:
    verdict = guard.check(Action(kind="shell", command=cmd))
    if verdict.blocked:
        raise PermissionError(verdict.summary)
    return subprocess.check_output(cmd, shell=True)