AIec

Guard threat model

6 min readdocs/GUARD_THREAT_MODEL.md

Guard governs the authority and communications of agent sandboxes from outside the guest. This document states what that does and does not defend against, in the terms a reader can check against the code and the acceptance runs.

The separation Guard depends on#

AIec control plane  ── places, fences, budgets, quarantine
AIec worker         ── owns the microVM and the Guard attachment
AIec Guard gateway ── DNS, model broker, credentials, packet rules
AIec Watchdog       ── observes authoritative telemetry, requests quarantine
guest               ── the agent's computer; not trusted

The sandbox may be compromised. The harness inside it may be compromised. The repository contents may be malicious. What still holds is that the network and credential boundary is enforced by processes the guest cannot reach or modify - and only that. It is a statement about where enforcement runs, not about what a host-level attacker can do afterwards; see 'What Guard does not defend' below.

Assets#

Asset Where it lives Who must not reach it
Model provider credential worker-side credential file the guest, always
Any tenant secret control-plane secret store the guest, always
Policy and its hash durable control-plane state the guest, always
Guard journal worker-side file plus remote sink the guest, always
Host network stack kernel the guest, always
Other sandboxes other attachments this guest
The control plane host the guest

Adversaries#

  1. A compromised guest. Arbitrary code as the sandbox user, arbitrary syscalls, arbitrary packets.
  2. A compromised harness. The model's tool-calling loop is attacker- influenced and may issue any request the tools allow.
  3. A malicious dependency or repository content. Code the agent runs is attacker-chosen.
  4. A confused or coerced operator. A human is talked into widening a policy.

What Guard defends#

What Guard does not defend#

Trust boundaries that matter#

Deployment modes and what each defeats#

Mode What it defeats What a compromise of that component defeats
Worker-host hardened process guest escape attempts; the default a root attacker on the worker host defeats the whole boundary
Separate gateway VM a compromise confined to the worker host that does not reach the gateway host the gateway host holds model credentials; its compromise reads proxied traffic
Separate physical gateway a compromised worker host with no route to gateway state the gateway itself is a single high-value target; latency and operational cost are real

Evidence discipline#

Every claim above that says "denied", "bounded" or "measured" names an artifact. benchmarks/guard-core-acceptance.json is a run on real microVMs with real nftables. benchmarks/guard-phase2-acceptance.json is the watchdog, dead-man and quarantine run. Claims not covered by an artifact are written as limitations, not as guarantees.