Conduct is presented by its maintainers as an open-source guardrail layer that intercepts LLM and MCP tool calls, applies centralized policies, and records decisions for auditability and least-privilege enforcement. The repository’s earliest cited artifact is Sudhi Seshachala’s “Initial commit — Delegator v0.1,” after which the project was apparently renamed or reframed as Conduct. The supplied web snippets establish that gateway-level inspection, tool-argument validation, policy enforcement, and audit logging are recognized agent-security patterns, but they do not independently verify Conduct’s implementation or capabilities.
Scott already holds and implements this position in SiloOS and the deterministic agent control plane: consequential tool calls should pass through an independent, least-privilege, auditable enforcement boundary. Conduct is currently an unverified additional implementation in a category the radar already tracks through Bulwark Gateway, Grith, and Runbook.v1; absent evidence of a distinct enforcement mechanism or independently validated capability, it does not materially extend Scott’s architecture.
ip:framework.siloosip:concept.runtime-governanceip:framework.decision-authority-infrastructuredev:concept.deterministic-agent-control-planeradar:bulwark-agent-security-gatewayradar:grith-coding-agent-security-proxyradar:runbook-mcp-fail-closed-workflowsradar:concept.mcp-securityradar:concept.security-proxies
queries asked of Scott's wikis
- least-privilege controls for coding agents
- MCP tool-call policy enforcement
- agent harness permission boundaries
- auditable agent action logs
- gateway versus harness-level guardrails
- capability security for autonomous agents
2026-09-05T13:26:18Z
The stale review adds no Conduct-specific validation, adoption, or technical differentiation, and no concrete follow-up is expected. Earlier corroboration applied to the broader control-plane pattern, not Conduct’s claimed enforcement capabilities; this unvalidated implementation no longer warrants active tracking.
2026-09-03T12:30:04Z
Jern Cloud and Oconee Runtime further establish model-external policy enforcement as a recurring implementation pattern, but remain repetitive category evidence without adoption, technical differentiation, or validation of Conduct itself. The case stays corroborated at the category level and low-value to Scott’s already implemented architecture.
2026-09-03T12:22:30Z
evidence attached: hn.story.49548892 — This explicit browser and coding-agent policy runtime independently corroborates the move toward enforceable, auditable tool-call controls.
2026-09-03T12:22:30Z
evidence attached: hn.story.49548975 — A repository-bound policy file is an independent implementation signal for enforcing coding-agent actions beyond prompt-level controls.
2026-09-01T12:28:17Z
Extensible-MCP adds another independent, released implementation of model-external policy enforcement, making the broader tool-call control-plane pattern corroborated rather than merely observed. It still does not validate Conduct’s specific enforcement claims, establish adoption, or reveal a distinctive mechanism.
2026-09-01T12:23:47Z
evidence attached: hn.story.49520552 — This independent open-source MCP proxy corroborates the emerging pattern of deterministic policy enforcement outside the model while reducing exposed tool schemas and context overhead.
2026-08-31T19:42:50Z
The new examples broaden the category evidence for constrained writes, verification, and runtime monitoring, but neither independently validates Conduct nor establishes adoption or a distinctive enforcement mechanism. The case remains an inspectable implementation within an increasingly crowded pattern Scott already tracks.
2026-08-31T19:24:37Z
evidence attached: hn.story.49513690 — A runtime security sensor for AI agents provides relevant independent context on deployable controls beyond prompt-level defenses.
2026-08-31T18:27:13Z
evidence attached: reddit.post.1w3h53u — A concrete agent-facing plugin using constrained writes and read-back verification materially contextualizes deployable tool-call guardrails.
2026-08-31T15:41:09Z
The added “Agentic Trust Controls” listing is repetitive category evidence without technical detail, adoption, or independent validation; it neither strengthens Conduct’s specific claims nor changes the case’s meaning for Scott.
2026-08-31T15:25:23Z
evidence attached: hn.story.49510612 — This appears to be another agentic trust-control effort, but the sparse listing provides no evidence beyond the existing guardrail episode.
2026-08-31T03:29:42Z
Steer provides another independent implementation of pre-execution tool-call interception, strengthening the category-level pattern enough to move beyond a seed. It still does not validate Conduct’s enforcement claims, reveal a distinctive mechanism, or show adoption.
2026-08-31T03:23:23Z
evidence attached: hn.story.49505003 — A second released tool-call interception layer independently supports the emerging pattern of enforceable pre-execution agent guardrails.
2026-08-30T17:28:49Z
A separate MCP gateway adds category-level evidence that policy interception, PII redaction, and auditing are becoming concrete implementation patterns, but it does not validate Conduct’s claims or distinguish its mechanism. Conduct remains an inspectable yet unverified example in an already crowded control-plane category.
2026-08-30T17:24:12Z
evidence attached: hn.story.49500475 — This is a concrete MCP gateway artifact adding in-flight PII redaction and audit capabilities to the open tool-call-control episode.
2026-08-28T20:43:37Z
No substantive evidence has arrived beyond a one-point engagement increase; Conduct remains an inspectable but unvalidated implementation of an already familiar control-plane pattern.
2026-08-28T20:37:21Z
grounded: known/low — Scott already holds and implements this position in SiloOS and the deterministic agent control plane: consequential tool calls should pass through an independen
2026-08-28T20:34:37Z
origin walked (codex/luna, conf 0.97): anchor hn.story.49483173 -> echo.github.41c811fa90 by Sudhi Seshachala
2026-08-28T20:32:18Z
case created — A directly linked open-source repository makes this a concrete and inspectable agent-security release.