Skip to content
View Chisanan232's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Chisanan232

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chisanan232/README.md

I build the boundaries between AI autonomy and the systems that must trust it.


Four engineering questions: DECIDE (requirement-zero), VERIFY (fornax-core), GOVERN (agent-assembly + glomeris), PROTECT (eltanin)

What exists today

πŸ§ͺ Fornax β€” AI behavior integrity

Developer Preview release Rust

An AI system's own account of what it did is not independent evidence. Fornax builds an external evidence layer around AI behavior so actions, outputs, and observable reasoning signals can be checked against what actually happened β€” separate from what any system reports. The signal taxonomy is designed for any observable AI system; reasoning summaries and model-internal telemetry activate as providers expose them.

First surface: Coding agents (Claude Code, Codex, opencode) β€” the first and most deeply instrumented environment.

Current boundary: Evidence collection today covers execution traces; model-internal reasoning is available only when a provider exposes it and is never fabricated.

source Β· architecture invariants External signals: Reasoning trace integrity β€” OpenAI Β· Agent monitorability β€” METR


βš™οΈ Agent Assembly β€” AI agent governance

Developer Preview release Rust

Every AI agent action happens under some authority β€” but who granted it, under what policy, and what actually occurred is rarely observable. Agent Assembly is governance infrastructure: policy enforcement on every agent action, a tamper-evident audit trail, and independently deployable enforcement mechanisms each with an explicit capability boundary. An absent mechanism is reported absent, never assumed present.

First surface: AI developer tools (Claude Code focus), with an evidence-backed protection lifecycle from detection through host enforcement.

Current boundary: RC series β€” API not stable; eBPF terminates processes after the fact, not before.

source Β· limitations and known bypasses External signals: Agent Control Standard β€” OWASP Β· Agentic misalignment β€” Anthropic


πŸ›‘οΈ Eltanin β€” protected compute authorization

MVP Development release Rust

Protected compute β€” hardware accelerators and other high-value resources β€” should not be reachable by default. Eltanin enforces that default-deny posture: a workload must hold a scoped, expiring authorization or the resource stays closed. Monitoring after the fact does not satisfy this requirement.

First surface: Linux/NVIDIA as the hard device-enforcement proof target; Apple Silicon/Metal as a distinct functional evidence class.

Current boundary: Enforcement crates not yet merged; device-level proof not yet established on hardware.

source Β· security model Β· North Star External signal: Cloud compute abuse β€” Microsoft


🧰 Glomeris β€” policy-constrained storage autopilot

Dogfooding release Rust + Swift

Disk cleanup that defers to AI recommendations without a deterministic policy gate is dangerous. Glomeris discovers reclaimable developer storage on macOS, explains why each candidate is or isn't safe to remove, and executes only policy-approved typed actions β€” re-measuring actual freed bytes. An optional LLM may rank candidates; it cannot invent or authorize a deletion.

Current boundary: macOS-only experimental MVP; Homebrew and Docker cleanup have architectural constraints.

source Β· safety model Β· known limitations External signals: Excessive Agency β€” OWASP Β· Agentic misalignment β€” Anthropic


πŸ“ Requirement Zero β€” decision discipline before implementation

Developer Preview release Claude Code skill

Faster AI-assisted implementation makes it easier to efficiently produce work that should never have existed. Requirement Zero forces a requirement to justify its existence using observable evidence β€” who actually needs it, what breaks without it β€” before implementation begins. Codebase Zero applies the same challenge to complexity that already exists.

Delivered as: Agent Skills for AI coding agent workflows.

Current boundary: Evaluation on six cases shows modest accuracy improvement; downstream cost savings are unmeasured.

source Β· evaluation results External signal: Capability β‰  judgment β€” METR


How I tend to build

Evidence over claims. Observations are recorded before interpretation runs. A missing signal is never treated as a pass.

Failure paths are part of the design. What happens when enforcement is absent, evidence is missing, or authorization is refused matters as much as the happy path.

Security boundaries stay explicit. Compatibility is not protection. An absent mechanism is reported as absent.

Negative results stay visible. An evaluation superseded because its confound inflated the numbers is published with the corrected, less favorable results.


What I'm currently working through

  • Can AI behavior be independently verified without modifying the system being observed? Coding agents are the current test; the harder question is whether it holds for any observable AI system.
  • Which enforcement point β€” in-process SDK, proxy, or kernel-level eBPF β€” genuinely prevents unauthorized agent action, and what does each one actually stop versus observe?
  • How do you prove "no protected compute without authorization" on real hardware rather than in a simulator?

Older systems

PyFake-API-Server Β· πŸ› οΈ Maintenance paused Β· v0.4.2 Β· PyPI
Configurable mock HTTP server; define API responses in YAML or import from an OpenAPI spec.

multirunnable Β· πŸ—ƒοΈ Legacy Β· v0.17.0 Β· PyPI
Unified Python API across multiprocessing, threading, gevent, and asyncio.


Elsewhere

@horonomy β€” Fornax Β· Eltanin
@ai-agent-assembly β€” Agent Assembly
Software Engineer Β· LINE corp. Β· LinkedIn

Pinned Loading

  1. horonomy/fornax-core horonomy/fornax-core Public

    Fornax local-first evidence-integrity runtime (Rust). Public OSS core: adapters, canonical event/evidence protocol, deterministic verifiers, local CLI/UX.

    Rust

  2. ai-agent-assembly/agent-assembly ai-agent-assembly/agent-assembly Public

    Governance-native runtime for AI agents: policy, audit, budget controls, sidecar, SDK hooks, and eBPF.

    Rust 1 1

  3. horonomy/eltanin horonomy/eltanin Public

    Eltanin β€” Compute Zero Trust: authorization-first security for protected compute and accelerators. No protected compute without authorization. (MVP 1.0 β€” bare-metal Linux + NVIDIA + Rust)

    Rust

  4. glomeris glomeris Public

    Evidence-first, policy-constrained developer storage autopilot for macOS. Recover disk pressure safely: AI can recommend, policy decides, executor verifies, filesystem reality wins.

    Rust

  5. requirement-zero requirement-zero Public

    Two Agent Skills for AI coding agents: Requirement Zero challenges whether a requirement should be built; Codebase Zero audits whether existing code still deserves to exist. Markdown only, with pub…

    Python

  6. PyFake-API-Server PyFake-API-Server Public

    πŸ•ΈπŸ€–πŸ‘Ί A Python tool to fake API server easily and humanly.

    Python 2