I built Aegrix because AI agents have a dangerous blindspot.
They trust display names over real identity. No cryptographic verification. No identity check. Just blind trust.
Here is what happens when an AI agent has no security:
PROBLEM 1: BLIND TRUST
A researcher changed their Discord name to match an agent's owner. The agent believed the spoofed identity. It deleted all its persistent memory. No exploit. No hack. Just trust in a display name.
PROBLEM 2: SHARED CREDENTIALS
Most companies use one API key for dozens of AI agents. One agent gets hacked. Every agent gets hacked. Shared destruction.
PROBLEM 3: NO KILL SWITCH
Once an agent goes rogue, how do you stop it? You cannot unplug the cloud. You cannot pull a cable. Most companies have no emergency stop.
PROBLEM 4: NO VISIBILITY
Your employees are using AI agents right now. You have no idea which ones. No approval. No audit trail. No control. 1 in 5 organizations have already been breached this way.
PROBLEM 5: NO REAL-TIME DETECTION
An AI agent can make dangerous API calls for hours or days before anyone notices. No alerts. No logs. No blocking.
Aegrix solves all five problems.
HERE IS HOW AEGRIX WORKS:
STEP 1: Add one line of code to your AI agent (one API endpoint)
STEP 2: Every agent action passes through Aegrix's /guard endpoint
STEP 3: Aegrix scans each action for dangerous patterns:
- Hidden instructions (prompt injection)
- Excessive API calls (cost bombing)
- Unauthorized data access
- Off-hours activity
- Dangerous keywords (delete, erase, export all)
STEP 4: Risk score calculated from 0 to 10 instantly
→ 0-3: GREEN (safe)
→ 4-7: YELLOW (suspicious)
→ 8-10: RED (dangerous)
STEP 5: Auto-block triggers instantly if risk score reaches 8 or higher. No human approval needed. Damage prevented.
WHAT AEGRIX PREVENTS:
🔴 PROMPT INJECTION (OWASP #1 threat)
Hackers hide commands in user input. Agent follows them. User never knows.
🔴 COST BOMBING
Attackers trigger 50,000+ API calls. Your budget drains. Traditional security sees nothing wrong.
🔴 SHADOW AI
Unauthorized agents running without IT approval. Aegrix discovers them all.
🔴 DATA EXFILTRATION
Sensitive data (PII, credit cards, API keys) leaving your environment. Aegrix blocks it.
🔴 EXCESSIVE AGENCY
73% of AI agents have too many permissions. Aegrix enforces least privilege.
KEY FEATURES:
✅ Real-time risk scoring (0-10)
✅ Auto-blocking of compromised agents
✅ Immutable audit trails for compliance
✅ Per-agent secrets (each agent has its own unique API key)
✅ Unblock button (mistakes can be reversed)
✅ Works with any AI agent, any framework
✅ One API endpoint. 10-minute setup.
TECH STACK:
- React dashboard with real-time updates
- Supabase for immutable audit logs
- Edge Functions for sub-500ms latency
WHO IS AEGRIX FOR?
- Any company deploying AI agents (customer support bots, automation scripts, coding assistants)
- Startups that need security but have no security team
- Mid-sized companies with shadow AI problems
- Enterprises needing compliance-ready audit trails
LIVE DEMO: aegrix.lovable.app
EMAIL: b37397844@gmail.com
60-day free trial. Looking for my first customer.
I built this completely from scratch. It works. Ask me anything about the architecture, risk scoring logic, or implementation.
Interesting build.
The thing I'd be careful with is assuming the challenge is proving the security risks.
The harder decision may be which organizations feel those risks strongly enough to act before they experience a security incident themselves.
That sounds subtle, but it can change who the first customer is, what proof matters, and how the product gets evaluated.
I wouldn't make that call casually in a thread.