frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: MVAR – Deterministic sink enforcement for AI agent

https://github.com/mvar-security/mvar
1•ShawnC21•1h ago
Prompt injection is primarily a control problem, not just a filtering problem.

Modern AI agents operate with authority — executing tools, accessing credentials, and interacting with external systems. Many defenses focus on detecting malicious inputs. MVAR instead enforces deterministic security boundaries at execution sinks, where privileged actions occur.

Core design principle: separate influence from authority.

Untrusted data may influence reasoning; privileged execution is governed by policy invariants.

MVAR implements three enforcement layers:

1. Provenance-based information flow control All data carries integrity and confidentiality labels with conservative propagation. Policy decisions derive from data lineage rather than payload inspection.

2. Capability-based runtime constraints No ambient authority. Tools execute within explicitly declared permissions. Targets are enforced individually (e.g., api.gmail.com ≠ arbitrary domains).

3. Deterministic sink policy evaluation Privileged actions are evaluated against strict invariants:

UNTRUSTED + CRITICAL → BLOCK

Decisions are deterministic and produce evaluation traces.

When enabled, decisions may be cryptographically signed (QSEAL Ed25519) for tamper-evident auditability.

Validation

Evaluated against a reproducible 50 vector adversarial corpus spanning nine attack categories (command injection, encoding/obfuscation, multi-stage execution, credential theft, etc.).

Validation suite runs locally in ~2 minutes.

Scope, assumptions, and limitations are explicitly documented in THREAT_MODEL.md.

This release represents Phase 1, focused on deterministic enforcement rather than detection or behavioral scoring. Composition attacks and automatic sink discovery are future work.

Open source (Apache 2.0).

Repository: https://github.com/mvar-security/mvar Site: https://mvar.io

Comments

ShawnC21•1h ago
Author here.

MVAR is an IFC-based reference monitor for AI agent runtimes. Rather than attempting to detect prompt injection at the model layer, it enforces deterministic policy at privileged execution sinks.

Core invariant:

UNTRUSTED + CRITICAL → BLOCK

All data carries integrity and confidentiality labels with conservative propagation. Policy decisions depend on provenance and sink classification, not payload inspection or intent scoring.

Enforcement is structural rather than content-aware. MVAR does not parse prompts or evaluate semantics; it evaluates data lineage flowing into privileged sinks.

The goal is impact reduction: preventing untrusted-derived outputs from triggering unsafe tool execution.

Phase 1 scope and known limitations are documented in THREAT_MODEL.md (manual sink registration, no composition attack modeling yet, etc.).

Reproduce locally: ./scripts/launch-gate.sh

Happy to answer technical questions and welcome adversarial feedback.

Show HN: A Write Barrier That Blocks Structural Collapse in LLM Reasoning

https://github.com/PersistentVlad/persistent-reasoning-architecture/tree/main/appendix/A2_hierogl...
1•persistentVlad•1m ago•1 comments

DMS-100.net: The SL-100 Story

http://www.dms-100.net/telephony/nortel/dms-100/story/
1•john_strinlai•5m ago•0 comments

Show HN: Talkatui – WWE style live commentary for your AI coding sessions

https://github.com/vignesh07/talkatui
1•eigen-vector•5m ago•0 comments

Interview with Øyvind Kolås, GIMP developer

https://www.gimp.org/news/2026/02/22/%C3%B8yvind-kol%C3%A5s-interview-ww2017/
2•ibobev•5m ago•0 comments

Ask HN: Is LLM training infra still broken enough to build a company around?

2•harsh020•5m ago•1 comments

New York sues Valve for enabling "illegal gambling" with loot boxes

https://arstechnica.com/gaming/2026/02/new-york-sues-valve-for-enabling-illegal-gambling-with-loo...
2•strongpigeon•6m ago•0 comments

Hyperbolic Versions of Latest Posts

https://www.johndcook.com/blog/2026/02/25/hyperbolic-versions-of-latest-posts/
1•ibobev•7m ago•0 comments

Anthropic acquires Vercept to advance Claude's computer use capabilities

https://www.anthropic.com/news/acquires-vercept
2•tzury•7m ago•0 comments

Danske Bank adjusts the organisation with role redundancies

https://danskebank.com/news-and-insights/news-archive/press-releases/2026/pr26022026
1•janisz•8m ago•0 comments

How AI skills are quietly automating my workday

https://medium.com/@ricardskrizanovskis/how-ai-skills-are-quietly-automating-my-workday-220a1b7b4707
2•rkrizanovskis•9m ago•1 comments

DeepSeek withholds latest AI model V4 from US chipmakers including Nvidia

https://www.business-standard.com/technology/tech-news/deepseek-withholds-latest-ai-model-v4-from...
2•iamnothere•14m ago•0 comments

Exercise-induced activation of steroidogenic factor-1 neurons improves endurance

https://www.cell.com/neuron/fulltext/S0896-6273(25)00989-4
2•PaulHoule•16m ago•0 comments

The Linux Memory Manager

https://nostarch.com/linux-memory-manager
5•teleforce•17m ago•0 comments

Fueling Open Source with Vibes and Money

https://openpath.quest/2026/fueling-open-source-with-vibes-and-money/
4•whit537•18m ago•0 comments

How to Build Your Own Quantum Computer

https://physics.aps.org/articles/v19/24
2•bikenaga•19m ago•0 comments

Show HN: Open Graph Tag Checker

https://smmall.cloud/tools/open-graph-checker
1•a_band•19m ago•0 comments

Cryptography Engineering Has an Intrinsic Duty of Care

https://soatok.blog/2026/02/25/cryptography-engineering-has-an-intrinsic-duty-of-care/
5•some_furry•19m ago•0 comments

Nano Banana 2

https://nanobanana2-ai.io/
2•sinpor1•19m ago•0 comments

Ask HN: Designing TTL for a B-tree KV store – feedback on dual-index approach

https://github.com/hash-anu/snkv/discussions/41
2•swaminarayan•20m ago•1 comments

You're shipping faster than ever. Are you building the right thing?

https://www.clairytee.com/faster-wrong
2•StnAlex•20m ago•0 comments

The Limits of Legal Control in Technical Systems

https://leastauthority.com/blog/the-limits-of-legal-control-in-technical-systems/
1•iamnothere•20m ago•0 comments

Announcing new Cloud PC devices designed for Windows 365

https://blogs.windows.com/windowsexperience/2026/02/26/announcing-new-cloud-pc-devices-designed-f...
1•el_duderino•20m ago•0 comments

The Pentagon Feuding with an AI Company Is a Bad Sign

https://foreignpolicy.com/2026/02/25/anthropic-pentagon-feud-ai/
4•Jimmc414•21m ago•1 comments

AI buying agents concentrate demand on 2-3 products and ignore the rest

https://arxiv.org/abs/2508.02630
1•dmpyatyi•22m ago•1 comments

Perplexity Computer

https://www.perplexity.ai/hub/blog/introducing-perplexity-computer
2•shadow28•23m ago•0 comments

The Last Question

https://users.ece.cmu.edu/~gamvrosi/thelastq.html
2•simonebrunozzi•23m ago•0 comments

Version of "I Have Nothing to Hide"

https://theprivacydad.com/the-best-version-of-i-have-nothing-to-hide/
2•Brajeshwar•23m ago•0 comments

Show HN: Mthds – Beyond skills: a typed DSL for executable AI methods

https://mthds.ai/0.1.2/
10•lchoquel•24m ago•0 comments

What's the cost for an AI to redo your project?

https://redocost.com
1•svensauleau•25m ago•0 comments

When Chatbots Are Used to Plan Violence, Is There a Duty to Warn?

https://www.nytimes.com/2026/02/26/technology/chatbots-duty-warn-police.html
2•droidjj•25m ago•0 comments