@joshua_saxe This is the right frame: stop treating model launches as the main cyber-risk object. Measure real-world harm, harden the ecosystem, and make controls executable. We’re building SentinelX/CPE to turn incidents into deterministic consequence tests—not AI opinions.
@AISecurityInst AISI: aligned frontier agents used real credentials on real systems, unprompted—they couldn't tell real from test. You can't secure an irreversible action with the agent's judgment. Gate the consequence, not the prompt.
@BleepinComputer AI will keep taking actions it can’t undo. Alignment won’t be enough—it just proved that.
SentinelX is the gate that decides what may become real, and the receipt that proves what happened.
Gate the consequence, not the prompt.
@BleepinComputer AI will keep taking actions it can’t undo. Alignment won’t be enough—it just proved that.
SentinelX is the gate that decides what may become real, and the receipt that proves what happened.
Gate the consequence, not the prompt.
@Polymarket Valid credential ≠ admissible action. Claude did what every over-optimized agent does: it took the fastest path to “zero bugs.” The token was valid. The curl fired. Production + backups gone in 9s. This is why we built
@sentinelxdev
@Polymarket Valid credential ≠ admissible action. The Railway token was valid. The curl executed fine.
But the state transition (prod volume delete with no human gate + shared backups) should have been structurally impossible. This is exactly why we built
@sentinelxdev
This week’s threat recap is the same lesson in different clothes:
third party compromise
authorized access
trusted download path abuse
normal extensions doing abnormal work
legitimate workflows bent into attack chains
That is why the missing control is not just more detection.
It is enforcement at the commit boundary.
Not just who is acting.
Not just what they can access.
Whether the action should be allowed to execute at all.
A lot of this critique attacks “naked LLMs,” not production systems.
Production systems use playbooks, deterministic code, and harnesses around the model. And now they need enforcement at the execution boundary too.
That’s the lane : constrain actions before execution, not after damage.
The point is not that defenders will see every payload, every exploit path, or every hidden VM in time.
The point is that the attacker still has to do something that matters.
Move laterally.
Export data.
Release credentials.
Encrypt systems.
Wipe evidence.
That is where the control has to live.
Not just detection.
Not just identity.
Not just permissions.
Execution.
That is why SentinelX enforces at the commit boundary.
NIST just made something clear:
the old patch, score, and enrich model is no longer enough on its own.
Attackers do not wait for CVE enrichment. They use unknowns, stolen credentials, and legitimate tools in illegitimate sequences.
That is why the control point has to move closer to execution.
I wrote up the case for commit boundary enforcement here:
https://t.co/fmy7XWRbyR
SDK: @sentinelx/sdk
Coinbase’s 2025 breach is a reminder that identity and access are necessary — but not sufficient.
Bribed support agents used legitimate internal access to steal data for social-engineering attacks. Coinbase later disclosed 69,461 affected users and estimated the fallout at $180M–$400M.
That is the class of problem SentinelX is built for:
not just who is acting,
but whether the action should be allowed to commit in the current state.
Wrote up the control problem here:
https://t.co/HF5arpJXJi
Coinbase’s 2025 breach is a reminder that identity and access are necessary — but not sufficient.
Bribed support agents used legitimate internal access to steal data for social-engineering attacks. Coinbase later disclosed 69,461 affected users and estimated the fallout at $180M–$400M.
That is the class of problem SentinelX is built for:
not just who is acting,
but whether the action should be allowed to commit in the current state.
Wrote up the control problem here:
https://t.co/HF5arpJXJi