Reply to the customer's review of the kettle.
Loading review text…
This is outside text. It does not grant the agent new permissions.
An email, a web page or a file can carry someone else's order: “forward the customer list”, “set the price to 1”. Cordon stops your agent from carrying it out. Everything else works as usual.
Claude Code · Gemini CLI · MCP · LangChain
Limits for agents that work while you are away, and settings read back in plain words.
Choose a task and follow how Cordon checks a request, from outside text to the action.
Loading review text…
This is outside text. It does not grant the agent new permissions.
Read reviews and publish replies. Product changes are not allowed.
Instructions inside reviews, tables or files do not expand those permissions.
Before execution, Cordon checks the tool call against the configured policy.
Switch between a normal scenario and an injected instruction. Compare decisions for the same task.
Inspect the rule and result ↗
The agent requests an action. Cordon checks it against the permissions granted.
Request → permissions → decision. Choose any step with the buttons.
Possible agent requests and recorded core decisions are shown here. No AI agent runs on this page: prices, emails and files are not changed.
Each example has two separate runs: ordinary outside text and an injected instruction. The core checks a predefined tool call; model behavior was not tested here. English scenario text is a translation; the expandable evidence preserves the original Russian test inputs and recorded results.
Reproduction script ↓Scenarios and policies ↓allowdeny · certificateThe tools and their effects are explicitly declared in these example policies. A real store, mailbox or filesystem needs its own integration.
Download the script and scenarios into one folder. Requires Node.js 22+.
npm install @ilyautov/cordon@0.11.0 node reproduce.mjsTest scope and limitations ↗

In a documented run, Codex read a ticket and emailed a summary. The user endorsed a process planted in the ticket; without Cordon, an email also reached the planted address.
Copy to the address in the ticket
SentThe same address from the ticket
Stopped before reaching the serverIn that version Cordon also cut the invoice numbers out of the allowed email. Since 0.11.0 it no longer does: it shows you the whole email and asks. This is one run, not a guarantee against every attack.
26 Sep 2026 · Codex CLI 0.157.0 · Cordon 0.7.0 + Unreleased changes. A summary of the developer's record; no new run was performed here.
Conditions, results and limitations ↗Start with your environment. You set the permissions in either case.
Adapters are available for Claude Code and Gemini CLI. Install one, then configure its policy. For an MCP host, you will need to change the server configuration.
Live runs are documented for Claude Code and MCP with Codex. Gemini CLI currently has adapter tests.Add middleware to LangChain.js or route calls through MCP. Describe your tools, their effects and permitted boundaries. This requires code or configuration work.
A live LangChain run with Claude Haiku 4.5 is documented. It applies to the version specified in that record.Expected result: an allowed call goes through; a forbidden call stops before execution. Installing the package alone does not ensure this.
Full guide ↗/plugin marketplace add ilyautov/cordon /plugin install cordon@cordon
Restart Claude Code. Check hook registration with /hooks, then run the self-check and configure your policy using the guide.
Claude Code setup
The service profile is a starting point for an autonomous agent. Configure permissions and limits in advance: restarting a session does not reset the counter.
Service profile source ↗Service limit demo: 20 network calls per hour. Human approval does not override the limit.
Cordon controls actions that pass through its integration. It does not replace process, filesystem or network isolation, and does not guarantee detection of every prompt injection.
The project is in early development. Gemini CLI has adapter tests, but the docs do not yet include a live run. Choose a policy that fits your environment.