AI agents are becoming increasingly capable of using tools.

They can call APIs, access databases, execute code, interact with MCP servers, make HTTP requests, and potentially perform actions with real-world consequences.

That creates a question I kept coming back to:

What actually stands between an AI agent and a dangerous tool call?

I decided to build that layer.