Session

Portcullis: Runtime Enforcement for AI Agent Tool Calls, Because Reviewing Tools Isn't Reviewing Act

AI agents are increasingly given direct access to tools: shells, APIs, file systems, browsers. Most current safety reviews stop at "is this tool safe to expose?" — but a tool's risk isn't fixed; it's defined by how it's invoked at runtime. A file-write tool used to save a log is fine. The same tool used to overwrite /etc/passwd is not. This talk introduces Portcullis, a research prototype for runtime enforcement of agent tool calls — policy checks that evaluate the actual call (arguments, context, sequence) rather than just the tool's existence. We'll cover the threat model, where static tool-allowlisting fails, the enforcement architecture, and open problems in policy expressiveness and latency tradeoffs.

Aakash Abhay Yadav

Managing CyberSecurity GRC | OWASP AI Exchange Author

San Francisco, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top