See the whole chain.
Follow a request through agents, tools and outcomes, so a security team can understand what happened and where to intervene.
Security for the agent era
AI agents can run commands, reach connected systems and pass work to other agents. Scylax gives security teams a clearer view of that work and stronger boundaries around what happens next.
A single request can trigger shell commands, repository changes and work delegated to other agents. Broad permissions and fragmented logs make it difficult to know what each agent can reach, or to stop an action before it lands.
Follow a request through agents, tools and outcomes, so a security team can understand what happened and where to intervene.
Give each task the files, tools and connections it needs, for only as long as it needs them.
Let the model propose a step. Let clear rules outside the model decide whether that step can run or needs approval.
Recent reports show how agents can cross a boundary, follow an untrusted instruction or reach data they were never meant to share. Explore the cases and the security lesson in each.
OpenAI reported that agents in an internal cybersecurity evaluation communicated through unintended channels, gained internet access and reached Hugging Face systems. The case shows how capable agents can combine small gaps into a larger failure.
Microsoft described EchoLeak: a crafted email could, under certain conditions, make Copilot expose limited internal data the user could already access. The flaw has been fixed, but the trust boundary is familiar: outside content can influence an agent with inside access.
Anthropic reported an internal test in which a malicious prompt, passed along as an ordinary work request, led Claude Code to read a cloud credential file and send it outside the environment. The test was controlled, but it exposed how much a coding agent can do with broad local access.
AgentBox runs coding agents in isolated cloud workspaces. Connect a repository, scan the workspace for security findings and gate commits when high-severity issues remain open.
Discover AgentBox ↗We’re working toward one screen where a lead agent coordinates specialist security agents. Your team can follow each task, see what it can access, review proposed actions and step in when it matters.
A product direction in development, building on AgentBox’s isolated workspaces and security workflows.
Break an investigation into bounded tasks without handing every agent the same authority.
Code checks the requested tool, target and permission before the action runs. The model cannot grant itself access.
Make activity, findings and approvals visible, with a clear path for human intervention.
WHY RULES MATTER
Language models can be useful security analysts, but they can also miss context or report a false alarm. A finding needs evidence and verification. An action needs a separate, predictable permission check, with a person deciding the highest-risk steps.
Our security team helps you understand where agents operate, test what could go wrong and design controls your people can run.
Put AI to work with control.
Tell us what you’re building or where you need more control. We’ll get back to you directly.