Skills
A flow-centric policy language cut confirmed agent compromise from 33% to 0% on AgentDojo while raising utility
AgentFlow specifies where data may travel in an agent system rather than which single actions are unsafe, using flow and path rules, task-scoped capabilities, controlled release, and stateful taint semantics enforced by a runtime monitor plus an SMT-based verifier. On AgentDojo's 949 cases it drops confirmed compromise from 33.0% to 0.0% and raises utility from 46.7% to 63.3%; on AgentDyn Dailylife it goes 73.5% to 0.0% with utility essentially unchanged, and ASB direct prompt injection lands at 0 successes in 1,200. Seven safety properties each verify in under half a second, which makes the policies checkable in CI.
↳ Follow the thread