Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

Brex Innovates AI Agent Security by Learning from Real Actions Instead of Predefined Rules

OpenClaw has gained popularity as an agentic framework but struggles at enterprise scale due to the need for real credentials and ineffective traditional guardrails. Brex developed CrabTrap, an open-source HTTP/HTTPS proxy that monitors all network traffic, applies policy rules, and uses a large language model (LLM) as a judge to approve or deny agent requests. By focusing on the network layer, CrabTrap makes nuanced enforcement decisions without needing SDK integrations, enabling framework- and language-agnostic agent governance. Rather than creating policies from scratch, Brex bootstrapped policy rules from actual agent behavior using a policy builder that runs agents in shadow mode. This approach proved more accurate and easier to manage. CrabTrap efficiently handles potential latency issues by activating the LLM judge on only a small fraction of requests and using smaller, faster models. Brex also tackled prompt injection by structuring requests as JSON to avoid manipulation. The system provides extensive audit trails, allows policy refinement through feedback loops, and enhances organizational confidence in deploying autonomous agents. Brex released CrabTrap as open-source to foster community contributions. Future improvements may include advanced authentication, role-based access control, escalation workflows, and automated policy lifecycle management. CrabTrap’s success demonstrates that enterprises can engineer solutions to AI agent governance challenges today, without waiting for the industry to develop perfect tools.

Venturebeat
Venturebeat