Cirvix adds session taint to stop AI agent secret exfiltration
Open-source authorization layer Cirvix introduced a session.touchedSecret flag: once an agent reads secret-shaped material, all external HTTP requests in that session are blocked. The deny-external-egress-after-secret rule closes the read-then-exfiltrate chain.
- touchedSecret is set when a session reads files matching .env, credentials, token, and never resets
- deny-external-egress-after-secret blocks http.request and net.* for external egress
- Deny always wins over allow; policy files can only tighten, never loosen
- Secrets fetched via handle secrets.get() do not taint the session and keep working
Read next
Security