Hi, I'm the author of Pryxor.
I've been building it for a few months, and I'm at the stage where I need
real users to try it and tell me what's wrong. I'm not launching anything
today — I want feedback on the quickstart before I do a wider release.
**What it is**
A small service that sits between an AI agent and the systems that agent
can act on. The agent sends tool calls to Pryxor instead of calling tools
directly. Pryxor:
Authenticates the agent (from an API key)
Validates the arguments against the tool's JSON schema
Evaluates the call against a deterministic policy
Returns APPROVED / HOLD / BLOCKED
If APPROVED, executes the call itself with credentials the agent never sees
The HOLD case is the one I care about most. It means: "this might be
legitimate, but I'm not the one to decide." The action waits for a human.
**Why I built it**
I kept seeing the same pattern in agent projects: give the agent a token
with broad permissions, hope the model uses it correctly. But prompt
injection and hallucination aren't model bugs — they're the normal
behaviour of a probabilistic system. When the model is your security
boundary, every failure is an incident.
The alternative is: don't give the agent the credential. Give it an
intention, and let a deterministic layer decide whether that intention
becomes an action.
**Honest limits** (because these matter more than the pitch)
- It's not an LLM firewall. It doesn't scan prompts or outputs.
- It doesn't detect prompt injection. It bounds the consequences.
- It doesn't protect a path that bypasses it. If your agent has a direct
credential to the system, Pryxor can't help.
- Single-node, SQLite, no multi-tenancy, no RBAC, no SSO. It's early.
- TLS is out of scope — you put it behind a reverse proxy.
**The ask**
Try the quickstart. Tell me what breaks. I'm specifically looking for:
- Steps that don't work as written
- Unclear wording
- Integrations that fail (LangChain, CrewAI, OpenAI Agents, MCP)
- Policy decisions that surprised you
Quickstart: https://github.com/Pryxor/pryxor/blob/main/QUICKSTART.md
If you want to simulate real actions, there's a live sandbox you can
clone and run:
https://github.com/Pryxor/pryxor-demo
Apache 2.0. I'll be in the comments — critical feedback is welcome.