📄 Sciences Methods and Technologies
International Journal (SciMeTech)

Volume 2 · Issue 2 · 2026
ISSN: 3085-5284
IAGA Sentinel: A Deterministic Multi-Layer Runtime for Zero-Trust AI Agent Governance
Edoardo Bambini
Pages 177–185 · Independent Researcher · IAGA, www.iaga.tech
Abstract
Autonomous AI agents are increasingly deployed with direct access to shell environments, file systems, databases, and external APIs, yet governance mechanisms remain either binary (allow/deny) or rely on opaque ML-based classifiers. We present IAGA Sentinel, a zero-trust security runtime implemented in 8,600 lines of Rust that interposes an 8-layer deterministic governance pipeline between the agent and its execution environment. Each layer produces an independent numeric risk contribution (0–100) feeding into a weighted composite scorer, replacing flat binary decisions with continuous, interpretable threat quantification across three decision bands: ALLOW (0–34), REVIEW (35–69), and BLOCK (70–100). We evaluate IAGA Sentinel on a primary suite of 800 governance requests across 16 scenarios and 9 attack categories, achieving 99.8% decision accuracy, zero false positives on benign actions, continuous risk scores from 1 to 88 with intuitive threat hierarchy, and sub-3 ms governance pipeline latency. We extend the evaluation with 5 obfuscation scenarios for a total of 1,050 requests; the production pipeline yields zero ALLOW bypasses on this extension. A targeted ablation that disables the firewall's signature-scan stage quantifies defense-in-depth: 50 of 250 obfuscation requests (20%) bypass to ALLOW with the stage removed, while 200 are still contained by overlapping detection from the threat-intelligence and policy layers. A composite-weight perturbation analysis bounds the system's sensitivity to weight choice within 1.24 percentage points across 8 configurations. IAGA Sentinel is source-available under the Business Source License 1.1.
Keywords: AI agent security, Zero-trust runtime, Composite risk scoring, Prompt injection, MCP governance

References

  1. Gravitee, "State of AI Agent Security 2026 Report," February 2026.
  2. Cisco, "State of AI Security 2026," Cisco Blogs, February 2026.
  3. NIST, "Request for Information Regarding Security Considerations for AI Agents," Federal Register, Doc. 2026-00206, January 2026.
  4. Y. Jia, Z. Shao, Y. Liu, J. Jia, D. Song, and N.Z. Gong, "A Critical Evaluation of Defenses against Prompt Injection Attacks," arXiv:2505.18333, 2025.
  5. OWASP, "Top 10 for Large Language Model Applications," 2025.
  6. J. Yi, E. Xie, J. Zhu, et al., "Benchmarking and Defending Against Indirect Prompt Injection," KDD '25, Toronto, Canada, 2025.
  7. E. Debenedetti, I. Shumailov, T. Fan, et al., "Defeating Prompt Injections by Design," arXiv:2503.18813, 2025.
  8. Z. Wang, N. Nagaraja, L. Zhang, H. Bahsi, P. Patil, and P. Liu, "To Protect the LLM Agent Against the Prompt Injection Attack with Polymorphic Prompt," arXiv:2506.05739, 2025.
  9. N. Maloyan and D. Namiot, "Prompt Injection Attacks on Agentic Coding Assistants: A Systematic Analysis," arXiv:2601.17548, 2026.
  10. F. Wu, E. Cecchetti, and C. Xiao, "System-Level Defense Against Indirect Prompt Injection Attacks: An Information Flow Control Perspective," arXiv:2409.19091, 2024.
  11. H. Zhang, J. Huang, K. Mei, et al., "Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents," Proc. ICLR 2025.
  12. B. Ramakrishnan and A. Balaji, "Securing AI Agents Against Prompt Injection Attacks," arXiv:2511.15759, 2025.
  13. Y. Liu, Y. Jia, R. Geng, J. Jia, and N.Z. Gong, "Formalizing and Benchmarking Prompt Injection Attacks and Defenses," USENIX Security '24, pp. 1831–1847, 2024.
  14. M. Andriushchenko et al., "AgentHarm: A Benchmark for Measuring Harmfulness of LLM Agents," Proc. ICLR 2025.
  15. A. Wei, N. Haghtalab, and J. Steinhardt, "Jailbroken: How Does LLM Safety Training Fail?" Advances in Neural Information Processing Systems (NeurIPS), 2023.
  16. K. Greshake, S. Abdelnabi, S. Mishra, C. Endres, T. Holz, and M. Fritz, "Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection," Proc. AISec '23 (16th ACM Workshop on Artificial Intelligence and Security), pp. 79–90, 2023.