Agent Guard: Kernel-Enforced Damage Boundaries for AI Agents via Human-Authorized Contracts
This paper presents Agent Guard, a Linux reference monitor that enforces human-authorized damage boundaries for AI agents by using eBPF-based LSMs to deterministically deny unauthorized file and network access while propagating strict "no-egress" states across process hierarchies, achieving significantly lower overhead than existing baselines.