LUVEO Technologies logo
LUVEO Technologies logo
Back home

Vark · 2026-10-03 · 9 min read

How We Built Vark: Engineering a Sub-Millisecond AI Agent Firewall in Pure TypeScript

Why existing cloud guardrails fail local AI agents, and how we engineered an 8-gate, sub-millisecond execution firewall in pure TypeScript with zero external dependencies.

When AI agents evolved from simple chat interfaces to autonomous software operators capable of running terminal commands, querying databases, and executing API calls, the security model of software changed overnight. Traditional web application firewalls (WAFs) and cloud guardrails were built to inspect HTTP payloads at the network perimeter. They were never designed to prevent an autonomous LLM loop from running rm -rf / or leaking .env secrets through an outbound curl command.

When we began building Saturn AI — our autonomous AI employee platform — we quickly realized that cloud-based LLM guardrails introduced two fatal flaws: Unacceptable Latency, with round-trips to cloud security APIs adding 100ms to 300ms of overhead per tool call and destroying the real-time responsiveness of local agent loops; and Contextual Blindness, because a remote cloud API has zero visibility into local filesystems, memory heaps, or OS process limits.

To solve this, we built Vark (@saturn/vark), an open-source, sub-millisecond execution firewall designed to sit inline between any AI agent runtime and downstream system capabilities.

┌─────────────────┐     ┌────────────────────────────────┐     ┌──────────────────┐
│   AI Agent /    │     │      Vark Security Engine      │     │  System Target   │
│ LLM Orchestrator├────►│  (8-Gate Inline Inspection)   ├────►│ (FS, Shell, API) │
└─────────────────┘     └────────────────────────────────┘     └──────────────────┘

The 8-gate pipeline model: Vark evaluates every tool execution request through an 8-gate sequential pipeline. If any gate throws an exception or detects an anomaly, the entire pipeline fails closed immediately.

Input Normalization Gate: normalizes incoming string payloads to Unicode NFKC, strips zero-width non-joiners and bidi directional overrides, and recursively decodes URL, Base64, Hex, and HTML-entity obfuscation layers up to a strict depth cap.

Runtime Schema Gate: uses an in-house, zero-dependency JSON Schema (Draft-07 subset) validator to strictly check and coerce argument types before any tool code executes.

Sub-Millisecond Circuit Breaker Gate: evaluates real-time failure thresholds and sliding-window error rates per tool, tripping automatically to prevent runaway retry loops.

Declarative Policy & Taint Tracking Gate: evaluates fine-grained role-based access rules (JSON/YAML) and verifies data provenance, ensuring untrusted external inputs cannot flow into sensitive tool sinks.

Human-In-The-Loop (HITL) Gate: intercepts designated high-risk capabilities (e.g., db:drop, stripe:refund) and pauses execution until an external signature or webhook callback releases the block.

Isolated Sandbox Gate: executes tool handlers inside isolated V8 heaps (isolated-vm / QuickJS WASM), Node worker threads with restricted permissions, or ephemeral virtual filesystems (memfs).

Output DLP & Stream Scanner Gate: scans execution return values — including Buffers and Streams — for PII, API tokens, and prompt reflection without consuming or mutating stream data.

Cryptographic Audit Gate: signs the invocation payload with an HMAC-SHA256 or Ed25519 signature and appends it to a tamper-proof, in-memory or file-backed hash chain.

To keep Vark's execution overhead below 1ms, we avoided heavy runtime dependencies. We wrote a custom schema validator optimized for monomorphic V8 shapes, implemented regex pattern arrays verified to execute in linear time to prevent ReDoS, and designed a lightweight, zero-allocation binary buffer scanner for Data Loss Prevention (DLP).

By keeping Vark 100% pure TypeScript and local-first, agents gain institutional-grade execution protection without making a single external network request. Read the code at github.com/luveo-technologies/vark.

Keep reading the source

All articles