
Multicorn Shield
Permissions, approvals & audit trails for AI agents
3 followers
Permissions, approvals & audit trails for AI agents
3 followers
AI agents today get full access or no access. There's no permission layer. Multicorn Shield intercepts every tool call before it executes, checks it against your permissions, and blocks anything unauthorized. Real-time approval requests, time-limited access, spending controls, and tamper-proof audit logs. Open source, works as an MCP proxy, 2-minute setup. Also includes free AI safety education at multicorn.ai/learn.









Quick update from me - I introduced a bug tonight that's impacting the plugin's ability to block Openclaw agent actions via the API. I've been debugging since 7pm and it's now 1am here in Sydney, so I'm calling it for tonight.
The recording and screenshots on the launch page show the full blocking flow working as intended - that's real, not faked. I broke something in a last-minute code change and I know where the issue is, just ran out of hours today. So please don't be disappointed if you test this out with OC and it doesn't work.
This is very much an early beta - I'm building this solo alongside a full-time job, so rough edges are expected. But the core architecture is solid and I'd genuinely love feedback on what permissions and controls matter most to you.
I'll be fixing this first thing tomorrow and will update here when it's resolved. Lots of exciting stuff on the roadmap too - content review gates, spending controls, and better feature gating so a last-minute change can't break the core blocking flow like this again.
In the meantime, the dashboard, landing page, and npm package are all live if you want to poke around.
Appreciate your patience - the irony of shipping a permissions tool that temporarily can't enforce permissions is not lost on me :sigh:
Update: the blocking flow was fixed earlier today and is live. v0.1.10 is on npm. The GIF on the README is from a real prod.
Still early, still rough around the edges, still building this solo after hours. But the core promise - your agent literally cannot act without your permission - that works now.