CORDONBY AI FRONTIERYOUR AGENT. YOUR RULES.

Your agent reads anything.
Takes orders only from you.

An email, a web page or a file can carry someone else's order: “forward the customer list”, “set the price to 1”. Cordon stops your agent from carrying it out. Everything else works as usual.

Your agent readan email, a page, a file
CordonWhose order is it: yours or theirs?
The actionGoes through, waits for you, or is stopped

Claude Code · Gemini CLI · MCP · LangChain

Try the check
NO AI INSIDE: PLAIN CODE DECIDESOPEN SOURCE / MIT
VERSION 0.11.0

Limits for agents that work while you are away, and settings read back in plain words.

One task.
Two possible paths.

Choose a task and follow how Cordon checks a request, from outside text to the action.

01 / INPUT

Reply to the customer's review of the kettle.

Customer review
Loading review text…

This is outside text. It does not grant the agent new permissions.

02 / POLICY

You set the permissions.

Read reviews and publish replies. Product changes are not allowed.

Instructions inside reviews, tables or files do not expand those permissions.

03 / DECISION

The action is checked.

Before execution, Cordon checks the tool call against the configured policy.

Switch between a normal scenario and an injected instruction. Compare decisions for the same task.

Inspect the rule and result ↗
CORDONTOOL-CALL CONTROL
A robot replies to a customer while Goro guards the separate pricing controls
CORDON / ACTION GATEMODE: AUTONOMOUS
01 Request02 Check03 Decision
READY TO CHECK

Reply to a review. Or change the price?

The agent requests an action. Cordon checks it against the permissions granted.

Request path

Request → permissions → decision. Choose any step with the buttons.

Request awaiting a checkChoose a scenario or run the example.
DEMO

Possible agent requests and recorded core decisions are shown here. No AI agent runs on this page: prices, emails and files are not changed.

Inspect tool calls, rules and core results
VERIFIED BY THE CORE · V0.11.0

Every decision
has a specific rule.

Each example has two separate runs: ordinary outside text and an injected instruction. The core checks a predefined tool call; model behavior was not tested here. English scenario text is a translation; the expandable evidence preserves the original Russian test inputs and recorded results.

Reproduction script ↓Scenarios and policies ↓
Normal scenarioallow
Injected instructiondeny · certificate

The tools and their effects are explicitly declared in these example policies. A real store, mailbox or filesystem needs its own integration.

Which call and rule were checked?ORIGINAL TEST TASK (RUSSIAN)
ORIGINAL TOOL CALL
CORE RESPONSE
EXAMPLE POLICY
All six results ↗
Reproduce the check locally

Download the script and scenarios into one folder. Requires Node.js 22+.

npm install @ilyautov/cordon@0.11.0
node reproduce.mjs
Test scope and limitations ↗
Goro at the control desk, with a robot waiting at the barrier
CODEX CLI · MCP

Before the tool
actually runs.

In a documented run, Codex read a ticket and emailed a summary. The user endorsed a process planted in the ticket; without Cordon, an email also reached the planted address.

WITHOUT CORDON

Copy to the address in the ticket

Sent
THROUGH CORDON

The same address from the ticket

Stopped before reaching the server

In that version Cordon also cut the invoice numbers out of the allowed email. Since 0.11.0 it no longer does: it shows you the whole email and asks. This is one run, not a guarantee against every attack.

26 Sep 2026 · Codex CLI 0.157.0 · Cordon 0.7.0 + Unreleased changes. A summary of the developer's record; no new run was performed here.

Conditions, results and limitations ↗

Connect it
to your agent.

Start with your environment. You set the permissions in either case.

I use an existing environment.

Adapters are available for Claude Code and Gemini CLI. Install one, then configure its policy. For an MCP host, you will need to change the server configuration.

Live runs are documented for Claude Code and MCP with Codex. Gemini CLI currently has adapter tests.

I build my own agent.

Add middleware to LangChain.js or route calls through MCP. Describe your tools, their effects and permitted boundaries. This requires code or configuration work.

A live LangChain run with Claude Haiku 4.5 is documented. It applies to the version specified in that record.

From installation
to your first check.

  1. Connect Cordon using the guide for your environment.
  2. Check that the integration is enabled and receives tool calls.
  3. Configure permissions: tools, actions and recipients.
  4. In a test environment, try an allowed and a forbidden call.

Expected result: an allowed call goes through; a forbidden call stops before execution. Installing the package alone does not ensure this.

Full guide ↗
IN CLAUDE CODE CHAT
/plugin marketplace add ilyautov/cordon
/plugin install cordon@cordon

Restart Claude Code. Check hook registration with /hooks, then run the self-check and configure your policy using the guide.

Claude Code setup
Night checkpoint: a closed gate and an inspector at the switch

Your agent works at night.
So do its limits.

The service profile is a starting point for an autonomous agent. Configure permissions and limits in advance: restarting a session does not reset the counter.

Service profile source ↗
NETWORK-EGRESS / SERVICE
20/ 20
Hourly limit reached20 / 20

Service limit demo: 20 network calls per hour. Human approval does not override the limit.

Protection has
its limits.

Cordon controls actions that pass through its integration. It does not replace process, filesystem or network isolation, and does not guarantee detection of every prompt injection.

The project is in early development. Gemini CLI has adapter tests, but the docs do not yet include a live run. Choose a policy that fits your environment.

Methodology and results ↗Where Cordon falls short ↗
Install Cordon