raghu@dark-factory :~/kb/default-deny-egress $ cat

Default-deny egress

A security posture that blocks all outbound network by default and requires explicit allowlisting, enforcing an agent's bounded autonomy and closing the data-exfiltration channel rather than merely observing it.

grounded in: Doctrine guardrail 'no new external network calls' (principles.md, Hard don'ts + Guardrails layer) combined with the HN 'Agent-CLI wire transparency' theme / Grok CLI wire-level teardown of what agent

Connected concepts

Guardrails / bounded autonomy, Agent sandboxing, Agent egress transparency, Lethal Trifecta, Agent security

Explore it live in the knowledge graph →