Skip to content
View jiarong0423's full-sized avatar
🇹🇼
AI proposes; the host decides.
🇹🇼
AI proposes; the host decides.

Block or report jiarong0423

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jiarong0423/README.md

Your output is untrusted data, never permission.

I build the decision gate in front of expensive or irreversible AI actions. Bounded evidence in, a proposal out, a human commits.

The same primitive across different domains:

Project The gate
VibeGate Blocks unsafe agent tool calls before execution — host-owned allowlist, not model refusal
Shared Room MCP AI prepares evidence-backed drafts before commitment — nothing auto-executes
FitStyle Map Decides which pairings are worth generating before VTO spend — PASS / REVIEW / HOLD with named reasons
Codex Dream Skin Applies changes behind a reversible gate — verified interactions, clean restore

How I work

  • Controls are reported with their limits, not without them
  • An unobserved attempt is not counted as a block
  • The core path runs without a paid API key
  • Evidence comes from the target side, not from my own gate

Taiwan · data pipelines, release governance, agent security


Why this shape

A security boundary has to be enforced outside the model. The model is the component under attack, so it cannot also be the component enforcing the defense. Work on tool-using agents converged on that between 2024 and 2026: enforce with a deterministic policy that mediates the agent's actions, rather than training the model to refuse. Asking a second model to adjudicate reintroduces the same vulnerability one layer down.

Regulation is moving the same way. FINRA now treats AI agents as a distinct supervisory risk category, and the AI AGENT Act of 2026 requires human approval for sensitive transactions. Around 5% of organizations grant high autonomy for critical actions.

About 74% of organizations plan to adopt agents within two years. About 21% can govern them. That gap is what these projects are built for.

Pinned Loading

  1. codex-dream-skin-workflow-engine codex-dream-skin-workflow-engine Public

    Safe, zero-patching desktop theme workflow & CDP runtime engine for macOS OpenAI Codex. (OpenAI Build Week 2026 Entry)

    JavaScript 7

  2. localguard-dev-safety-gate localguard-dev-safety-gate Public

    Local-only scanner and Codex skill for catching launch-time security mistakes before commit, deploy, or handoff. No network requests, no exploitation.

    JavaScript

  3. match-the-fit-public-demo match-the-fit-public-demo Public

    Public FitStyle Map demo source with bounded review logic and protected algorithm boundary.

    TypeScript

  4. shared-room-mcp shared-room-mcp Public

    Shared Room MCP reference app powered by Adaptive Contract MCP: WebMCP reads state, AI prepares drafts, humans approve commitments.

    JavaScript

  5. vibegate-security-playground vibegate-security-playground Public

    Agentic security playground for Strands SDK & Amazon Nova. Demonstrates runtime tool interception with zero-execution evidence against prompt injection.

    Python

  6. ai-security-rules ai-security-rules Public

    Read-only local security gate & scanner for AI coding workflows, MCP, and package hallucination risks.

    Python