Scanners-Box 每日 AI 工具推荐 Scanners-Box Daily AI Tool Picks
AI 智能体运行时管控 AI Agent Runtime Controls
共 2 个工具 · 专栏每天 14:00(北京)更新一期 2 tools · one new issue daily at 14:00 GMT+8
微软开源的 AI Agent 运行时管控套件:把「请 AI 守规矩」换成「让 AI 没法不守规矩」 Microsoft's runtime governance suite for AI agents: from "asking AI to behave" to "making it structurally incapable of misbehaving"
微软 2026-03 开源,MIT。每次工具调用前插确定性策略闸门,违规抛 GovernanceDenied;附带零信任身份与 kill switch,可上 CI 卡 OWASP/NIST/EU AI Act 合规。最大短板:策略未加载时默认 allow 静默失效。
MIT, open-sourced 2026-03. Inserts a deterministic policy gate before every tool call, message and delegation — violations raise GovernanceDenied. Adds SPIFFE/DID identity and a kill switch; CI can gate OWASP/NIST/EU AI Act compliance. The catch: fails open when no policies are loaded.
https://github.com/microsoft/agent-governance-toolkit
面向自主 AI Agent 的安全私有运行时:用声明式 YAML 策略在文件系统、网络、进程、凭证四个维度设界,凭证只在策略放行后注入授权端点 A safe, private runtime for autonomous AI agents: declarative YAML policies enforce boundaries across filesystem, network, process and provider access, and credentials only flow into policy-admitted endpoints
Rust 写的 AI Agent 安全运行时,声明式 YAML 策略在文件 / 网络 / 进程 / 凭证四维度设界,三态拦截(允许 / 绑凭证 / 拒);凭证从不落盘,只在策略放行后注入端点。NVIDIA 官方出品,目前 alpha,0.1.0 即将发布。
AI-agent secure runtime in Rust: declarative YAML policies gate filesystem, network, process and provider access with a three-state outbound filter (allow / bind credentials / deny). Credentials never touch disk and are injected only into policy-admitted endpoints. Officially from NVIDIA, currently in alpha.
https://github.com/NVIDIA/OpenShell