Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Read by thought-leaders and decision-makers around the world. Phone Number: +1-650-246-9381 Email: pub@towardsai.net
228 Park Avenue South New York, NY 10003 United States
Website: Publisher: https://towardsai.net/#publisher Diversity Policy: https://towardsai.net/about Ethics Policy: https://towardsai.net/about Masthead: https://towardsai.net/about
Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Founders: Roberto Iriondo, , Job Title: Co-founder and Advisor Works for: Towards AI, Inc. Follow Roberto: X, LinkedIn, GitHub, Google Scholar, Towards AI Profile, Medium, ML@CMU, FreeCodeCamp, Crunchbase, Bloomberg, Roberto Iriondo, Generative AI Lab, Generative AI Lab VeloxTrend Ultrarix Capital Partners Denis Piffaretti, Job Title: Co-founder Works for: Towards AI, Inc. Louie Peters, Job Title: Co-founder Works for: Towards AI, Inc. Louis-François Bouchard, Job Title: Co-founder Works for: Towards AI, Inc. Cover:
Towards AI Cover
Logo:
Towards AI Logo
Areas Served: Worldwide Alternate Name: Towards AI, Inc. Alternate Name: Towards AI Co. Alternate Name: towards ai Alternate Name: towardsai Alternate Name: towards.ai Alternate Name: tai Alternate Name: toward ai Alternate Name: toward.ai Alternate Name: Towards AI, Inc. Alternate Name: towardsai.net Alternate Name: pub.towardsai.net
5 stars – based on 497 reviews

Frequently Used, Contextual References

TODO: Remember to copy unique IDs whenever it needs used. i.e., URL: 304b2e42315e

Resources

Free: 6-day Agentic AI Engineering Email Guide.
Learnings from Towards AI's hands-on work with real clients.
Capability Tokens for AI Agents: A Security Kernel in Python
Latest   Machine Learning

Capability Tokens for AI Agents: A Security Kernel in Python

Last Updated on August 19, 2026 by Editorial Team

Author(s): Diogo Santos

Originally published on Towards AI.

Your agent has 1,000 tools and no idea which ones it’s allowed to call. agent-kernel gives every tool call an HMAC capability token, a policy gate, and a tamper-evident audit trail — in-process, in two dependencies.

Your agent works. You wired up an LLM, handed it a pile of MCP tools, and watched it plan, call list_invoices, summarize the result. Demo-day magic.

Capability Tokens for AI Agents: A Security Kernel in Python

The article argues that most agent frameworks are unsafe in practice because tool registries are effectively flat, tool outputs flow straight back into the prompt, and logs are often insufficient to answer “who did what, and under whose authority.” It presents agent-kernel (weaver-kernel) as a small Python security kernel that sits between an LLM loop and tools, enforcing capability-based authorization for every tool call and producing a tamper-evident, hash-chained audit trail. It explains the end-to-end lifecycle (register → grant → invoke → expand → explain), detailing how HMAC-signed, time-bounded capability tokens prevent confused-deputy attacks via binding to both principal and capability, how a deterministic policy engine decides whether tokens are minted (including roles, sensitivity classes, field whitelisting, row caps, and rate limits), how a context firewall redacts and bounds raw tool output before it reaches the model (and downgrades unsafe “raw” modes for non-admins), and how ActionTrace records are chained for tamper evidence (with candid limitations around truncation and headless verification). The post concludes with a quickstart, practical limitations of the alpha state (token signing vs encryption, heuristic regex redaction, truncation detectability, in-process-only rate limiting), where agent-kernel fits in the broader Weaver stack, and key takeaways for building agents that handle sensitive or destructive actions.

Read the full blog for free on Medium.

Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.

Published via Towards AI


Towards AI Academy

We Build Enterprise-Grade AI. We'll Teach You to Master It Too.

15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.

Start free — no commitment:

6-Day Agentic AI Engineering Email Guide — one practical lesson per day

Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages

Our courses:

AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.

Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.

AI for Work — Understand, evaluate, and apply AI for complex work tasks.

Note: Article content contains the views of the contributing authors and not Towards AI.