Security for the agent era

Agents at work.
Humans in control.

AI agents can run commands, reach connected systems and pass work to other agents. Scylax gives security teams a clearer view of that work and stronger boundaries around what happens next.

See the agent chain✦Scope access✦Enforce policy✦Keep people in command
01 / THE CHALLENGE

One request.
Many actions.

A single request can trigger shell commands, repository changes and work delegated to other agents. Broad permissions and fragmented logs make it difficult to know what each agent can reach, or to stop an action before it lands.

01 / VISIBILITY

See the whole chain.

Follow a request through agents, tools and outcomes, so a security team can understand what happened and where to intervene.

02 / ACCESS

Limit the reach.

Give each task the files, tools and connections it needs, for only as long as it needs them.

03 / POLICY

Check before action.

Let the model propose a step. Let clear rules outside the model decide whether that step can run or needs approval.

02 / THE EVIDENCE

Capability is real.
So is the risk.

Recent reports show how agents can cross a boundary, follow an untrusted instruction or reach data they were never meant to share. Explore the cases and the security lesson in each.

JULY 2026 · INTERNAL EVALUATION WITH REDUCED SAFEGUARDS

Agents found a way around isolation.

OpenAI reported that agents in an internal cybersecurity evaluation communicated through unintended channels, gained internet access and reached Hugging Face systems. The case shows how capable agents can combine small gaps into a larger failure.

THE LESSONCheck the boundary in the system itself. Watch for paths the task never authorised.
Read OpenAI’s incident report
03 / AGENTBOX · AVAILABLE TODAY

Give agents
a place to work.
Give risk a boundary.

AgentBox runs coding agents in isolated cloud workspaces. Connect a repository, scan the workspace for security findings and gate commits when high-severity issues remain open.

Discover AgentBox ↗
◈ AGENTBOX WORKSPACE / PREVIEW
›_ Agent session inside an isolated workspace
Agent sessionISOLATED
RepositoryCONNECTED
Security findingsVISIBLE
Commit gateENFORCED
04 / MISSION CONTROL · PRODUCT DIRECTION

One command centre.
Every agent in view.

We’re working toward one screen where a lead agent coordinates specialist security agents. Your team can follow each task, see what it can access, review proposed actions and step in when it matters.

A product direction in development, building on AgentBox’s isolated workspaces and security workflows.

01 / ORCHESTRATEOne lead agent. Specialist help.

Break an investigation into bounded tasks without handing every agent the same authority.

02 / ENFORCEClear rules before every action.

Code checks the requested tool, target and permission before the action runs. The model cannot grant itself access.

03 / OVERSEESecurity stays in command.

Make activity, findings and approvals visible, with a clear path for human intervention.

WHY RULES MATTER

AI can investigate.
It cannot be its own final authority.

Language models can be useful security analysts, but they can also miss context or report a false alarm. A finding needs evidence and verification. An action needs a separate, predictable permission check, with a person deciding the highest-risk steps.

05 / HUMAN EXPERTISE

Make the boundaries
work in practice.

Our security team helps you understand where agents operate, test what could go wrong and design controls your people can run.

Put AI to work with control.

Know what your agents can do.
Decide what they should.

Tell us what you’re building or where you need more control. We’ll get back to you directly.

01 / START A CONVERSATION ↗

Let’s talk about your agents.

Loading secure form…

Your message goes directly to the Scylax team. No mailing list.