⚡
AgentForge
Security

Security by Design

Capability-based zero-trust security. Trust nothing, verify everything.

Zero-Trust Architecture

Zero-Trust Principles

AgentForge implements capability-based security, not trust-based security. Every agent starts with zero permissions. You explicitly grant only what it needs.

Each agent receives an HMAC-signed capability token that specifies:

  • Filesystem Paths: Which directories the agent can read/write (glob patterns)
  • Network Domains: Which external APIs the agent can call
  • Token Budget: Maximum tokens the agent can consume
  • Timeout: Maximum execution time

How Capability Enforcement Works

Every tool call is checked against the agent's capability token:

Tool Call Request
  ↓
Enforcer.Check(capability, action)
  ↓
Is action allowed?
  → YES → Execute tool
  → NO  → Return error "Permission denied"

ACL Examples

# Restrictive (trusted worker)
agentforge spawn worker \
  --fs-allow "/home/user/work/**" \
  --domain-allow "api.openai.com" \
  --token-budget 100000 \
  --timeout 300

# Moderate (content creator)
agentforge spawn content-creator \
  --fs-allow "/home/user/content/**" \
  --fs-allow "/home/user/media/**" \
  --domain-allow "api.openai.com" \
  --domain-allow "github.com" \
  --domain-allow "*.wikipedia.org" \
  --token-budget 500000 \
  --timeout 1800

# Permissive (research agent)
agentforge spawn researcher \
  --fs-allow "/home/user/**" \
  --domain-allow "*.com" \
  --token-budget 1000000 \
  --timeout 3600

Attack Mitigations

AttackMitigation
Arbitrary file accessFilesystem ACLs restrict to specific paths. Cannot access /etc/, other users, or unmounted paths.
Uncontrolled network callsDomain whitelist prevents exfiltration or SSRF attacks.
Runaway costsToken budget enforced. Agent stops when budget exhausted.
Infinite loopsHard timeout kills agent. Cannot be overridden by agent.
Privilege escalationEach agent is independent goroutine. Cannot affect other agents or host system.
Unauthorized command executionShell_exec with argument safety. Proper quoting and escaping enforced.

Audit & Logging

Every action is logged:

  • Agent spawn/termination
  • Capability token generation and validation
  • All tool invocations
  • ACL violations (denied requests)
  • Token budget updates and exhaustion
  • Memory modifications
  • Cost tracking per agent

Access the audit log via the dashboard or agentforge logs CLI.

Best Practices

  • Apply Principle of Least Privilege: Start restrictive, grant permissions only as needed.
  • Monitor Costs: Set realistic token budgets. Review daily costs.
  • Rotate Tokens: Periodically rotate capability tokens (recommended: monthly).
  • Audit Regularly: Review security logs for denied requests or anomalies.
  • Isolate by Department: Use department ACLs to separate content, SEO, social teams.
  • Test ACLs: Verify agents get "permission denied" for disallowed paths/domains.

Compliance & Standards

AgentForge supports compliance scenarios:

  • GDPR: Agents can be restricted to specific regions. Memory store is self-hosted.
  • HIPAA: All processing stays on-premises. No external API calls without explicit allowlist.
  • SOC 2: Full audit trail, capability-based access control, isolated agent execution.

Security Architecture

┌─────────────────────────────────────────────────────────────┐
│                    AgentForge Daemon                        │
└─────────────────────────────────────────────────────────────┘
              │              │              │
              ↓              ↓              ↓
    ┌──────────────┐ ┌──────────────┐ ┌──────────────┐
    │   Agent 1    │ │   Agent 2    │ │   Agent 3    │
    │ (token: abc) │ │ (token: def) │ │ (token: ghi) │
    └──────────────┘ └──────────────┘ └──────────────┘
         │                │                │
         ↓                ↓                ↓
    ┌──────────────────────────────────────────────────┐
    │     Capability Enforcer (Verification Layer)     │
    │  - Validates token signature                     │
    │  - Checks filesystem ACL                         │
    │  - Checks domain whitelist                       │
    │  - Verifies token budget                         │
    │  - Enforces timeout                              │
    └──────────────────────────────────────────────────┘
         │                │                │
    ✓ ALLOWED       ✓ ALLOWED       ✗ DENIED
         ↓                ↓                ↓
    Execute Tool    Execute Tool    Return Error
    Log Success      Log Success      Log Violation

Ready to Deploy Securely?

Read the full documentation or contact us for enterprise security reviews.

View Documentation