Skip to content

Feedback for “Agentveil”: competitive landscape needs citations, and why now is not landed #84

Description

@will-lamerton

Two gaps in the framing sections, both cheap to close.

The competitive landscape has no citations

Tools like Clampd provide Rust runtime security pipelines but optimize for detection rules (240+ rules) rather than strict allowlisting. Diplomat-agent uses a two-tier approach but relies heavily on AST scanning. Pipelock and OpenAFW are network-side proxies

Four projects, one specific figure, no links and no dates. In a fast moving space a reader cannot check any of it, and the claims will silently rot. Links plus the date the comparison was made would fix it.

The comparison most readers will want is also missing: how shipped coding agents already sandbox local execution. Claude Code and Codex CLI both confine tool execution using OS primitives (Seatbelt on macOS, Landlock or bubblewrap style containment on Linux). That is the closest prior art to Agentveil's core idea, it is in production, and it is not mentioned. Engaging with it makes the positioning stronger, not weaker, because those implementations are per agent, opinionated, and closed to policy authorship, which is precisely the gap Agentveil is arguing for.

"Why now" is not landed

The process page asks for "problem named clearly, with 'why now' landed". The Problem section describes a condition that has been true since agents got tool access. It never says why 2026 is the moment.

The material is all there in the surrounding text, it just needs a paragraph:

  • MCP server proliferation. Every new server is new capability granted to an agent by a third party, and the whitepaper already flags that MCP tool descriptions can change between runs.
  • Autonomy modes shipping in mainstream CLI agents, where the user has explicitly turned confirmation off.
  • Indirect prompt injection moving from a demonstrated weakness to documented incidents in the wild.
  • Agents moving into CI and background runs where there is no human to answer a Review prompt at all, which is a case the current design does not cover and may want to name.

What would help: links and a dated "as of" line in Competitive landscape, a paragraph on the shipped agent sandboxes, and a "why now" paragraph closing the Problem section.

Raised during the public review window (closes 2026-09-19).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions