Agent permissions are easy to widen by accident. This repo keeps them task-scoped.
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
Agent permissions are easy to widen by accident. This repo keeps them task-scoped. Tenuo is a capability-based authorization toolkit for AI agents that call tools and delegate work. It helps you constrain what an agent can do per task by attaching a signed warrant to the work, with limits on tools, arguments, holder, and expiry. Key features: • Signed warrants – define which tools an agent may call, under what constraints and for how long • Argument constraints – restrict concrete tool inputs, such as a staging-only cluster and replica cap • Subtractive delegation – child warrants can drop
Posted by Dan Kornas (99.2k followers) 2 h ago · 5 likes · 678 views · view the original post on X. Kept by the Dev Radar as Security.
More dev work like this
- People still aren't getting it! So going to spell it out for you as to why you want this… — @PixelRainbowNFT
- Tbh this is pretty reasonable. Another axis of scaling: — @teortaxesTex
- rogue agents and prompt injection are currently considered the biggest unresolved threat… — @cantinasecurity
- Slashy for enterprise I don’t publicly talk about often — @GaddipatiHarsha
- Excited to continue pushing out talks and discussions from our Open Source AI Summit! — @PresidioBitcoin
- Cyber attackers move fast, so defenders have to move faster 🚨 — @cerebras
- We're excited to be in Okta's XAA, allowing AI agents to securely gain scoped access to… — @browserbase
- 🚰 SYSTEM PROMPT LEAK 🚰 — @elder_plinius
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 22.2k posts from 5k X accounts over the last 21 days, 2.6k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-23 07:13 UTC. Full method.