DEV Community

StarkGate
StarkGate

Posted on

Why LLM Guardrails Are Failing AI Agents — And How We Built a Deterministic Firewall Instead

As developers, we are shipping AI agents deeper into production environments. We give them tools, API keys, database access, and shell execution rights to maximize their autonomy.And then this happens: an unsupervised agent loops out, hallucinates a destructive system command (rm -rf), drops a production table, or leaks a .env secret containing database credentials.The traditional way the market tries to solve this is through LLM-based guardrails (an AI watching another AI). But let's be honest: that approach is probabilistic, slow, susceptible to prompt injection, and leaves zero replayable cryptographic evidence when things break.That is why we built StarkGate.What is StarkGate?StarkGate is a fully deterministic decision engine that sits as an external firewall between your AI agent and the real world.Before any high-stakes action executes—whether it's a wire transfer, a file deletion, an outbound email, or a physical actuator command—it must pass through StarkGate. The engine evaluates the action against your strict enterprise rules in microseconds, returning a definitive ALLOW or DENY.Core Architecture PrinciplesZero LLM in the Loop: The decision path is 100% deterministic and stateless. No fuzzy thresholds, no probabilities.Fail-Closed by Default: If the network drops, keys rotate mid-flight, or payloads are malformed, StarkGate defaults to DENY. When in doubt, a firewall must act like a locked door, not a suggestion box.Tri-Engine Parity (Zero Drift): To guarantee identical behavior everywhere, we implemented the core engine across three environments locked down by golden vectors in CI:TypeScript (Cloudflare Workers): For global edge production deployments.Python (starkgate-sdk on PyPI): For local development, CI pipelines, and offline verification.Rust (no_std + WASM, $\le$ ~310 KB): For hardened Kubernetes clusters down to embedded microcontrollers.33 Pure Operators & Advanced NodesStarkGate uses bounded, closed comparison operators to evaluate payloads without arbitrary logic injection:Numeric: gt, lt, gte, lte, eq, between, not_between, modStrings & Paths: contains, matches_regex, starts_with, path_matches (bounded JSONPath)Arrays & Geolocation: in, count_gt, in_bbox, distance_ltIt also supports advanced nodes like field-to-field comparisons ($ref to ensure transaction amounts stay below account balances) and complex computations (sum(quantity * price) > cap).Cryptographic Proofs for Compliance (EU AI Act Ready)Every verdict emitted by StarkGate is bundled into an immutable evidence package consisting of:Ed25519 Signatures & HMACChain-linked Audit Hashes (sha256: linking back to previous events)Merkle Tree Anchoring published to transparency logsThis means auditors, regulators, or your Chief Risk Officer can verify verdicts offline—even if your cloud servers are entirely powered down. It provides native compliance infrastructure for the incoming EU AI Act regulations.Multiple Integration DoorsYou can plug StarkGate into your stack via whatever control point fits best:Python SDK: pip install starkgate-sdkMCP Server: npx starkgate-mcp-server to wire it directly into AI assistants.OS FileGuard: Protect local file paths via Windows ACLs or Linux Landlock.REST API & Docker/K8sCheck It OutStarkGate is completely open-source (MIT), and our live sandbox is available right now.🌐 Explore the Guide & Test It: https://sentinel-api.wenjoseph16.workers.dev/guide🚀 Time-to-first-rule: Under 5 minutes from signup to blocking your first risky action.Let's build autonomous agents that are powerful and safe by design. Feel free to drop your thoughts, feedback, or security edge cases in the comments below!

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.