Josselin Guarnelli

Josselin Guarnelli

Founder @ Diplomat · AI agent security

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

  • diplomat-agent
    diplomat-agentFind unguarded tool calls in your AI agent code
    Apr 2026
  • 🎉
    Joined Product HuntApril 29th, 2026

Forums

diplomat-agent - Find unguarded tool calls in your AI agent code

We scanned 16 AI agent repos (Skyvern, Dify, CrewAI, PraisonAI, Khoj). 76% of tool calls with real-world side effects, payments, emails, DB writes, deletes, had zero runtime protection. diplomat-agent finds them : pip install diplomat-agent diplomat-agent scan . Zero config. Zero deps (stdlib only). AST, not regex. Outputs: terminal, JSON, SARIF 2.1.0, CSAF 2.0, and toolcalls.yaml — a Behavioral BOM of every side effect your agent can trigger. Maps to OWASP Agentic Top 10. Apache-2.0.
View more