Security by Design
Capability-based zero-trust security. Trust nothing, verify everything.
Zero-Trust Architecture
Zero-Trust Principles
AgentForge implements capability-based security, not trust-based security. Every agent starts with zero permissions. You explicitly grant only what it needs.
Each agent receives an HMAC-signed capability token that specifies:
- Filesystem Paths: Which directories the agent can read/write (glob patterns)
- Network Domains: Which external APIs the agent can call
- Token Budget: Maximum tokens the agent can consume
- Timeout: Maximum execution time
How Capability Enforcement Works
Every tool call is checked against the agent's capability token:
Tool Call Request
↓
Enforcer.Check(capability, action)
↓
Is action allowed?
→ YES → Execute tool
→ NO → Return error "Permission denied"ACL Examples
# Restrictive (trusted worker)
agentforge spawn worker \
--fs-allow "/home/user/work/**" \
--domain-allow "api.openai.com" \
--token-budget 100000 \
--timeout 300
# Moderate (content creator)
agentforge spawn content-creator \
--fs-allow "/home/user/content/**" \
--fs-allow "/home/user/media/**" \
--domain-allow "api.openai.com" \
--domain-allow "github.com" \
--domain-allow "*.wikipedia.org" \
--token-budget 500000 \
--timeout 1800
# Permissive (research agent)
agentforge spawn researcher \
--fs-allow "/home/user/**" \
--domain-allow "*.com" \
--token-budget 1000000 \
--timeout 3600Attack Mitigations
| Attack | Mitigation |
|---|---|
| Arbitrary file access | Filesystem ACLs restrict to specific paths. Cannot access /etc/, other users, or unmounted paths. |
| Uncontrolled network calls | Domain whitelist prevents exfiltration or SSRF attacks. |
| Runaway costs | Token budget enforced. Agent stops when budget exhausted. |
| Infinite loops | Hard timeout kills agent. Cannot be overridden by agent. |
| Privilege escalation | Each agent is independent goroutine. Cannot affect other agents or host system. |
| Unauthorized command execution | Shell_exec with argument safety. Proper quoting and escaping enforced. |
Audit & Logging
Every action is logged:
- Agent spawn/termination
- Capability token generation and validation
- All tool invocations
- ACL violations (denied requests)
- Token budget updates and exhaustion
- Memory modifications
- Cost tracking per agent
Access the audit log via the dashboard or agentforge logs CLI.
Best Practices
- Apply Principle of Least Privilege: Start restrictive, grant permissions only as needed.
- Monitor Costs: Set realistic token budgets. Review daily costs.
- Rotate Tokens: Periodically rotate capability tokens (recommended: monthly).
- Audit Regularly: Review security logs for denied requests or anomalies.
- Isolate by Department: Use department ACLs to separate content, SEO, social teams.
- Test ACLs: Verify agents get "permission denied" for disallowed paths/domains.
Compliance & Standards
AgentForge supports compliance scenarios:
- GDPR: Agents can be restricted to specific regions. Memory store is self-hosted.
- HIPAA: All processing stays on-premises. No external API calls without explicit allowlist.
- SOC 2: Full audit trail, capability-based access control, isolated agent execution.
Security Architecture
┌─────────────────────────────────────────────────────────────┐
│ AgentForge Daemon │
└─────────────────────────────────────────────────────────────┘
│ │ │
↓ ↓ ↓
┌──────────────┐ ┌──────────────┐ ┌──────────────┐
│ Agent 1 │ │ Agent 2 │ │ Agent 3 │
│ (token: abc) │ │ (token: def) │ │ (token: ghi) │
└──────────────┘ └──────────────┘ └──────────────┘
│ │ │
↓ ↓ ↓
┌──────────────────────────────────────────────────┐
│ Capability Enforcer (Verification Layer) │
│ - Validates token signature │
│ - Checks filesystem ACL │
│ - Checks domain whitelist │
│ - Verifies token budget │
│ - Enforces timeout │
└──────────────────────────────────────────────────┘
│ │ │
✓ ALLOWED ✓ ALLOWED ✗ DENIED
↓ ↓ ↓
Execute Tool Execute Tool Return Error
Log Success Log Success Log Violation
Ready to Deploy Securely?
Read the full documentation or contact us for enterprise security reviews.
View Documentation