01Fail-closed by default, denying unknown tools, incomplete payloads, or ambiguous target scopes.
02Every decision (allow/deny) is appended to an immutable, SHA-256 hash-chained evidence log.
03Curated 'ops layer' rules catch catastrophic misconfigurations like privileged containers or public S3 buckets.
042 GitHub stars
05Evaluates structured tool invocations against OPA policy bundles, providing deterministic results and actionable hints.
06Kill-switch for AI agents, blocking destructive operations unless proven safe.