New · Open source · Apache-2.0 / MIT
Vark.
A sub-millisecond execution firewall for AI agent tool calls. Vark sits between agent runtimes and system capabilities — even a fully compromised model can't execute what Vark blocks. Entirely offline, zero telemetry.
<2ms
Overhead per call
8
Pipeline gates
0
Cloud dependencies
100%
Open source
The pipeline
Every tool call runs 8 gates. Fail one, get blocked.
Normalize
Unicode NFKC, strips zero-width/bidi tricks, folds homoglyphs, recursively decodes URL/Base64/Hex/HTML layers.
Schema
Arguments validated against the tool's JSON Schema before execution — zero-dependency Draft-07 validator.
Breaker
Per-tool error thresholds halt cascading agent loops in under a millisecond.
Policy + Taint
Role-based YAML/JSON rules plus data provenance — untrusted web context never reaches sensitive arguments.
HITL
High-risk ops (db:drop, stripe:refund) pause for async human approval or a signed webhook.
Sandbox
Tool logic runs in isolated V8 heaps, permission-locked workers, or containers with copy-on-write virtual filesystems.
DLP
Outputs scanned for PII, secrets, entropy anomalies, and tracking leaks — without mutating streams.
Audit
Every invocation HMAC/Ed25519-signed into a tamper-proof, append-only hash chain.
Threat detection & DLP
Catches what blocklists miss.
- Multilingual injection & jailbreak scanning across obfuscated formats
- On-device semantic similarity checks against known threat clusters
- Honeytoken canaries that freeze sessions on echo-back
- Entropy scoring that catches memory dumps and prompt reflection
- Reversible PII pseudonyms, restored only at authorized egress
- Credential scanning for AWS, GCP, Azure, OpenAI, Anthropic, GitHub & more
Sandboxing & hardening
Execution with no way out.
- V8 isolate sandboxes with strict memory ceilings and timeouts
- Ephemeral copy-on-write virtual filesystem with automatic rollback
- Shell AST parsing + strict argv exec — never shell: true
- Path traversal & TOCTOU defense via realpath, O_NOFOLLOW, re-verification
Policy, MCP & access control
Rules the model can't talk its way around.
- Declarative YAML/JSON policies with dry-run evaluation
- MCP tool pinning by SHA-256 against rug-pull modifications
- Taint tracking from untrusted sources to sensitive sinks
- Ephemeral credential broker — the LLM never sees raw secrets
- SSRF egress proxy with DNS pinning and metadata-IP blocks
- Rate, cost, token, and output-size quotas per tool and identity
CLI & observability
Built for real workflows.
$ vark check <file>
Dry-run tool calls against policy
$ vark audit verify <log>
Verify cryptographic hash chains
$ vark policy test <policy>
Unit-test declarative policies
Deterministic replay
Exact 1:1 post-mortem replays
OTel + SIEM
Splunk, Datadog, webhooks
State stores
In-memory + Redis adapters
SDK adapters
Saturn, OpenAI, Anthropic, Vercel, LangChain, LlamaIndex
At a glance
Free forever. Self-host in minutes.
Apache-2.0 / MIT. No cloud, no telemetry, no tiers. Read the code, run it locally, ship it on-premise.
