SigmaShake · Books
Cover of AI Agent Guardrails by Charles Chong

AI Agent Guardrails

A practitioner's handbook for containing autonomous coding agents — tool-call gates, OS sandboxing on Linux/macOS/Windows, MCP hardening, red-teaming — with a dated, citation-backed survey of twenty real guardrails products and a runnable lab in every chapter, against your own machine.

$5 one-time · EPUB + PDF · instant download

Get the book

One-time purchase. Instant download link by email after checkout.

24chapters
136,146words
93code listings
24hands-on labs
254citations verified
10diagrams

Inside the book

Three of the book's ten original diagrams — real figures from the manuscript, not marketing illustrations.

Diagram: The Seven Control Points — the book's seven-layer containment model, from the prompt layer and the tool-call gate down through process containment, the kernel, filesystem and secrets, network egress, and audit and response.

The mental model the rest of the book builds on: seven places a coding agent's actions can be stopped, each covered in its own chapter.

Diagram: The Kill Chain — Where It Actually Stopped. Shows delivery, interpretation, execution, defense evasion, objective, and aftermath, with three worked cases showing a real guardrail that blocked, missed, or asked for human confirmation at execution.

Three worked cases tracing where a real guardrail actually intervenes in an attack — blocked, missed, or asked.

Diagram: OS Containment — Same Four Questions, Three Mechanisms. Compares Linux namespaces and seccomp-bpf, macOS App Sandbox and Seatbelt/SBPL, and Windows AppContainer and Job Objects across the same four containment questions.

Every containment technique in the book covered for Linux, macOS, and Windows — never just one platform.

What you'll build

AI Agent Guardrails is a practitioner's handbook for containing autonomous coding agents on machines that matter — a laptop with SSH keys and cloud credentials, a CI runner with a deploy key, a shared workstation with a company's source tree checked out. A coding agent that reads a file, runs a shell command, and fetches a URL is not a bigger autocomplete: it is a program that writes and executes other programs, steered by text that can arrive from anywhere — a pull request, a README, a hostile MCP tool description. Across 24 chapters, author Charles Chong builds a reference architecture of containment layers — tool-call interception, OS and kernel sandboxing on Linux, macOS, and Windows, network egress control, evaluation and red-teaming — and names twenty real guardrails products against a five-layer taxonomy, stating plainly where each is stronger than his own SigmaShake Governance (SSG). Every technical claim carries a citation and a retrieval date.

Get the book

One-time purchase. Instant download link by email after checkout.

What's inside

The Problem

  1. The Agent Is Not a Chatbot
  2. The Agent Threat Landscape
  3. Anatomy of an Incident
  4. A Reference Architecture

Interception

  1. Hooks: Where to Stand
  2. Policy as Code
  3. Allowlisting and Denylisting
  4. Hardening MCP
  5. Prompt-Layer Defenses and Their Limits

Containment

  1. Sandboxing on Linux
  2. Sandboxing on macOS
  3. Sandboxing on Windows
  4. Kernel Hardening for Agent Hosts
  5. Secrets, Filesystem, and Resource Containment

Perimeter

  1. Network Egress Control
  2. Antivirus, EDR, and the Agent Process
  3. Threat Intelligence for Agent Runtimes

Measurement and Response

  1. Evaluating Guardrails
  2. SHAKEDOWN: Building a Defender Benchmark
  3. Red-Teaming Your Agent
  4. AI-DR: Detection and Response

Practice

  1. The Guardrails Product Landscape
  2. Rolling Out Guardrails at Scale
  3. Building Your Own Guardrail