@tomjwxf logo

@tomjwxf

Free

Building zero trust infrastructure for AI agents

FreeFree tier
Type
Open Source
Company
ScopeBlind Pty Ltd

About @tomjwxf

TJF (tomjwxf) is an ex-Hedge Fund manager building zero-trust infrastructure for AI agents. Their open-source projects on GitHub include a security gateway for MCP servers with Cedar policy engine and Ed25519-signed receipts, offline verification tools for signed artifacts, and an agent governance toolkit covering policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Key repositories include scopeblind-gateway, VeritasActa/verify, VeritasActa/Acta, cedar-policy/cedar-for-agents, and microsoft/agent-governance-toolkit. These tools aim to provide secure, verifiable, and policy-controlled interactions for AI agents and machine decisions.

Key Features

Security gateway for MCP servers with Cedar policy engine and Ed25519-signed receipts
Per-tool enforcement and finance mandate gate (Legate) with proof packs
Offline verification of signed receipts and artifacts (no server, no account, no trust required)
Open protocol for signed, verifiable machine decisions with hash-chained audit trails
AI Agent Governance Toolkit with policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering (covers OWASP Agentic Top 10)
Multiple IETF Internet-Drafts and patents
Compatible with npx protect-mcp

Pros & Cons

Pros
  • Open source with Apache-2.0 license
  • Active development with patents and IETF Internet-Drafts
  • Focus on security and verifiability for AI agents
  • Comprehensive governance toolkit covering multiple security aspects
  • No server or account required for offline verification
Cons
  • Early stage projects with limited documentation outside code
  • Niche focus on zero-trust AI infrastructure may not suit general use
  • Dependence on GitHub for distribution and community support

Best For

Securing AI agent communications with policy-based access controlVerifying integrity and authenticity of machine decisions and artifactsEnforcing zero-trust principles on AI tool execution and data flowBuilding audit trails for autonomous AI agent actionsImplementing agent governance and compliance in enterprise environments