Lelu – authorization engine that catches manipulated AI agents
Four decision outcomes including compute redirect—prompt injection detected before policy runs.
Open source authorization engine for AI agents. Confidence-aware gating · Human-in-the-loop review · Policy-as-code · Full audit trail
Catches when authorized agents are being manipulated, not just blocking unauthorized access.
Developers building production AI agents
OPA · Casbin · AWS Verified Permissions
Four decision outcomes including compute redirect—prompt injection detected before policy runs.
Okta for who can access, Lelu for when agents are being manipulated.
First open-source scanner for AI agent skill supply-chain attacks.
Stateful detection across sessions beats single-message guardrails used by Lakera and Protect AI.
Isolated LLM with no tools or memory makes prompt injection hit a dead end.
Demonstrates RCE in AI agents by bypassing untrusted content tags via fake redirects.