2026-10-11 17:11 UTC

Conduct’s maintainers claim its open-source guardrail layer can enforce and audit policies on LLM and MCP tool calls, providing agents with a deployable least-privilege control point.

state: expiredheat: lowuncertainty: highknownscott: lowagentic-security mcp agent-harnessesConduct

What is this?

Conduct is presented by its maintainers as an open-source guardrail layer that intercepts LLM and MCP tool calls, applies centralized policies, and records decisions for auditability and least-privilege enforcement. The repository’s earliest cited artifact is Sudhi Seshachala’s “Initial commit — Delegator v0.1,” after which the project was apparently renamed or reframed as Conduct. The supplied web snippets establish that gateway-level inspection, tool-argument validation, policy enforcement, and audit logging are recognized agent-security patterns, but they do not independently verify Conduct’s implementation or capabilities.

Why it matters to Scott

Scott already holds and implements this position in SiloOS and the deterministic agent control plane: consequential tool calls should pass through an independent, least-privilege, auditable enforcement boundary. Conduct is currently an unverified additional implementation in a category the radar already tracks through Bulwark Gateway, Grith, and Runbook.v1; absent evidence of a distinct enforcement mechanism or independently validated capability, it does not materially extend Scott’s architecture.
ip:framework.siloosip:concept.runtime-governanceip:framework.decision-authority-infrastructuredev:concept.deterministic-agent-control-planeradar:bulwark-agent-security-gatewayradar:grith-coding-agent-security-proxyradar:runbook-mcp-fail-closed-workflowsradar:concept.mcp-securityradar:concept.security-proxies
queries asked of Scott's wikis
  • least-privilege controls for coding agents
  • MCP tool-call policy enforcement
  • agent harness permission boundaries
  • auditable agent action logs
  • gateway versus harness-level guardrails
  • capability security for autonomous agents

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (10) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Conduct, open-source guardrails for LLM and MCP tool callssudhendra1203
🟧 echo.github ⭐The repository’s earliest primary artifact is Sudhi Seshachala’s “Initial commit — Delegator v0.1.” The project was later renamed/reframed aSudhi Seshachala——
🟧 hnEnterprise MCP Gateway: In-Flight PII Redaction and Audit in GoBenjaminJ10
🟧 hnSteer: Deny or rewrite an AI agent's tool calls before they runmalucelli20
🟧 hnAgentic Trust Controlsmooreds183
🟠 redditI gave Claude Code write access to my WordPress SEO fields. Here's what I built so it couldn't quietly wreck anything.
ClaudeAI
NipunArora03
🟧 hnTwo sentences our security scanner can't tell apart and how we solved it with MLdelphiaisec10
🟧 hnShow HN: A Proxy between LLMs and MCP servers with policy the model cannot reachbanuakman20
🟧 hnJern Cloud – a coding agent bound by a policy file in your repositoryademar10
🟧 hnShow HN: Oconee Runtime – Policy enforcement for browser AI and coding agentshthomas420

Interpretation history

Decision trace