CHIMERA -- Def Acc Hackathon
Janos Mozer, Jaca Gregorio, Tallosy Peter · Team Badcompany
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Autonomous AI agent security is fragile because it relies on probabilistic LLM guardrails, enabling data exfiltration and Confused Deputy attacks. Our vSAML architecture solves this by decoupling policy from the LLM using cryptographic Macaroons and a Taint Tracking Rule Engine to deterministically revoke external tools (like web search) the instant an agent accesses confidential data, providing mathematically verifiable defense against insider and outsider threats posed by any type of prompt injection attacks.

Reviews
No public critique yet.
Cite this project
@misc{mozer2025chimera,
title = {{CHIMERA -- Def Acc Hackathon}},
author = {Janos Mozer and Jaca Gregorio and Tallosy Peter},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/chimera-def-acc-hackathon-qw3d}},
url = {https://apartresearch.com/sprints/projects/chimera-def-acc-hackathon-qw3d}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Assisted Audit of Solana Programs
Assisted Audit of Solana Programs
GLAM
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …