Customer-input inspection
Inspect messages, attachments, and externally controlled text before they reach the model, helping identify instruction overrides and other untrusted customer content.
Koreshield is a runtime security layer for AI support workflows that inspects customer input, retrieved context, and proposed actions before they influence a model or execute a tool call. It helps support, engineering, and security teams detect threats, review evidence, and enforce policies in stages.
Koreshield is a runtime security layer for AI support workflows. It evaluates customer input, retrieved context, and proposed actions before they become trusted instructions or executable tool calls, with separate decisions at each boundary.
Teams can begin in detect mode alongside live traffic, review decision evidence and false positives, and move to enforcement when the workflow’s fallback behavior is understood. The product is designed to add a security decision close to the support workflow rather than replace the organization’s authorization system.
Inspect messages, attachments, and externally controlled text before they reach the model, helping identify instruction overrides and other untrusted customer content.
Screen tickets, CRM notes, and RAG documents so externally controlled material is not treated as system-authoritative instructions.
Evaluate proposed tool calls against trust, approval, and authorization limits before an action runs.
Run beside live traffic in detect mode to record threats without interrupting requests, then use enforce mode to stop requests that violate policy.
Record the reason for each decision and retain request evidence for reviewing expected behavior, misses, and false positives.
Use a server-side scan key and connect the FastAPI security service with PostgreSQL to a hosted console or existing support infrastructure.
Run inspection beside production support traffic without blocking requests, then review detections and false positives before changing policy or enabling enforcement.
Check customer messages and attachments for instruction overrides before they reach a support model or influence its response.
Screen CRM notes, poisoned tickets, and RAG documents so retrieved material does not silently inherit system authority during answer generation.
Assess refund, account, or other proposed tool actions against trust, approval, and authorization limits before execution.
Use retained evidence and decision reasons to validate benign and adversarial support cases with security, support, and engineering stakeholders.
Koreshield is intended to run close to the support workflow. The documented deployment boundary is a FastAPI security service with PostgreSQL, connected to the hosted console or the organization’s own support infrastructure.
The documented rollout is to create a server-side scan key, run detect mode beside live traffic, review evidence, misses, and false positives, and enable enforcement only when fallback behavior is understood.
Koreshield records the reason for each decision and can retain evidence associated with inspected requests. The demo also describes outputs including decision, severity, confidence, and retained evidence.
It evaluates three workflow boundaries independently: customer input before model execution, retrieved context such as tickets or RAG documents, and proposed tool actions before execution.
The site states that Koreshield does not replace an authorization system, does not promise complete attack coverage, does not inspect arbitrary files or images today, and does not make high-risk agents autonomous.
CreateOS Sandbox is an isolated compute environment for running code and agent workloads inside Firecracker micro-VMs. It is designed for workflows that need machine-level isolation, private networking between sandboxes, and programmatic control through SDK, CLI, or MCP.
Codex Plugins bundle reusable skills, app integrations, and MCP servers into workflows you can install in the Codex app or use from Codex CLI. They help extend Codex with connected-service tasks, reusable instructions, and shared team workflows.
Wallie is an open-source AI streamer that watches your screen, hears chat, and generates live commentary in a configurable persona. It runs locally on your machine with your own keys and is aimed at faceless content, autonomous streams, and real-time reactions.
AakarDev AI helps teams manage AI provider access, project-level setups, logs, and analytics from one dashboard. It supports BYOK workflows and lists providers including OpenAI, Google Gemini, Anthropic, Groq, Mistral AI, and Perplexity AI.
Trigger.dev chat agent is a durable AI chat backend for developers building stateful conversations that can survive refreshes, crashes, and long-running turns. It connects with the AI SDK `useChat` flow and runs on managed infrastructure with no timeout on a turn.
Whirr is a quiet macOS menu bar app that mirrors Claude Code activity to your notch. It helps Mac users glance at agent progress without keeping a terminal window open.