scriptkittyos · coming soon

the problem

AI agents act.
Who said they could?

Every enterprise wants agents. Almost none can deploy them, because nobody can answer the only question that matters: what is this agent actually allowed to do, and can you prove what it did? Script Kitty OS is where I build and publish the answer.

=^.^= holytrinity · authority gate
agent proposes : send_wire($48,200 → acct •••9954) approval bound to : acct •••7741 · $48,200 · valid 90s state changed? : yes · target differs from grant ────────────────────────────────────── decision : DENY · authority mismatch receipt : #a3f9…c1 sealed · tamper-evident ────────────────────────────────────── gate offline? nothing runs. fail closed.

the system

HolyTrinity: an authority control plane for AI agents

Guardrails watch what agents say. HolyTrinity governs what agents do. It sits between any agent and the systems it touches, and it holds four invariants that detection alone cannot:

gate before execute

Every action passes the authority gate before it runs. Not logged after. Not sampled. Mediated, pre-execution.

approval bound to the act

An approval attaches to specific effect content with a validity window, not to a session or a pattern. If the target changes between grant and execution, the approval dies with it.

fail closed

If the gate is unavailable, nothing runs. Availability is never traded for authority.

proof packets

Every decision seals a tamper-evident receipt: who authorized what, bound to which content, decided when. Evidence an auditor can hold.

The agent can be fooled. The authority can't.

the receipts

Built by someone who broke these systems first

This work grows out of years of adversarial AI research: proving how agents get hijacked, then building the layer that makes the hijack not matter.

8 system cards The ART agent red-teaming benchmark, from the paper I co-authored (arXiv:2507.20526), is cited in eight frontier model system cards.
DEF CON 33 Designed and ran the in-person AI red-teaming competition: format, design, and the floor itself.
Built on the BEAM Elixir/OTP supervision and isolation, chosen because authority infrastructure has to stay up while everything around it fails. Published research ↗

the timing

The deadline isn't mine. It's regulatory.

OMB M-25-21

Federal agencies must identify and manage High-Impact AI, and use cases that fail the minimum practices must be discontinued. The reporting deadline lands September 2026.

whitehouse.gov · Apr 2025 ↗

CISA + Five Eyes agentic AI guidance

"Strong governance, explicit accountability, rigorous monitoring and human oversight are not optional safeguards but essential prerequisites."

Careful Adoption of Agentic AI Services · cisa.gov · 2026 ↗

the cats

Yes, the cats are real.

Script Kitty runs on rescue cats and open-source pet tech, and one day the platform gets a physical home: a hacker cat café where you can pop shells and foster kittens in the same room. The Script Kitty Foundation carries that mission.

Script Kitty Foundation