thomassprayberry

Agent security · AI infrastructure · Autonomous systems

Thomas Sprayberry

I build the control-plane layer for autonomous agents — the action firewall, the secrets broker, the supply-chain gate, and the reliability primitives that let an agent fleet touch real systems without handing it the keys — and I run an entire software studio, Sprayberry Labs, on that fleet, in production.

4 frameworks governed · 68,560 skills scanned · OpenSSF Scorecard 9.4, verified live · every claim links to a real PR or release

SEE THE PROOF ↓ GITHUB ↗ RÉSUMÉ EMAIL ↗

§1Proof — watch it, then verify it

Don't take my word for it. Click in.

A control plane that governs agent frameworks it has never seen, an open firewall benchmark, a 68,560-skill supply-chain sweep, a 9.4/10 OpenSSF Scorecard on a package that ships itself, and the fleet shipping a real fix end to end. Every link below resolves to a real pull request, CI run, npm package, or post — nothing staged.

Featured · live · the strongest signal

One firewall, four unrelated agent frameworks — governed end to end

I put my agent firewall (redstamp) in front of a CrewAI Flow (Python), a LangGraph StateGraph (JS), OpenAI's own Agents SDK, and Microsoft AutoGen — each fully governed without patching the framework: the poisoned tool stripped before the model can load it, a destructive rm -rf / blocked at the gate, and every verdict written to a tamper-evident audit that breaks if you edit it. The gate sits below the framework, at the MCP protocol layer, so it holds no matter what's upstream. One framework could be a trick; four unrelated ones is a structural property.

Watch the fleet work

VERIFY IT YOURSELF — every repository here is public, MIT-licensed, and CI-green. Clone any of them and re-run the checks: redstamp, truecopy, strongroom, fieldpass, dario, deepdive, agent-security-stack. dario, deepdive, truecopy, strongroom, and fieldpass install straight from npm — every publish tokenless from CI via OIDC trusted publishing, with SLSA provenance.

§2Selected work

What I've built, in the open.

  1. askalf — a self-hosted AI workforce platform

    An autonomous agent fleet that runs a whole software studio end to end: intake → tickets → specialist agents → pull requests, with its own nervous system, shared memory, scheduling, and guardrails. I designed it and I operate it daily.

  2. Own Your Stack — the agent-security control plane

    The boundary between an agent and its tools: vet the tool, contain the call, give it a credential it never holds — and prove every decision. redstamp and strongroom run in enforce mode on my production fleet today, and redstamp governs any MCP-speaking framework (CrewAI, LangGraph, OpenAI's Agents SDK, Microsoft AutoGen) from below.

    • redstamp — a deterministic, offline action firewall that decides what a tool call may do before it runs: green/yellow/red/black risk tiers, secret-exfil and prompt-injection blocking, tamper-evident audit — plus arena, an open agent-firewall benchmark. Enforced in prod. /redstamp ↗
    • strongroom — an agent secrets broker that hands out scoped, short-lived, single-use leases instead of raw keys, audits every access — and lets a parent agent delegate a narrower sub-lease to a sub-agent, attenuation-only: scopes can shrink, never widen. Enforced in prod. /strongroom ↗
    • truecopy — the supply-chain gate: vet, sign, and pin every skill and MCP server before it loads — and the daily watch re-verifying the official plugin directory in CI. /truecopy ↗
    • fieldpass — a governed browser for agents: indirect prompt injection quarantined before the model sees it, dangerous actions gated — 8/8 planted payloads withheld on real Chrome, and the headline 2025–26 agentic-browser attacks reproduced as an offline incident suite, all stopped. /fieldpass ↗
  3. dario — a self-healing LLM proxy

    An OAuth LLM proxy with an autonomous release pipeline I built on top of it: it detects when an upstream dependency drifts, rebakes, runs full CI, and self-publishes a new npm release — no humans in the loop — with a supply chain hardened to match: OpenSSF Scorecard 9.4/10, a 100% Best Practices badge, signed and SLSA-attested releases. Routes any tool through one local endpoint on your own subscription pool. Open source, MIT, 300+★.

  4. deepdive — a research agent you can trust by construction

    One command, one cited answer: plan → search → headless fetch → extract → synthesize, every call through your own router. Built on deterministic trust signals, because citation-verification alone scores content farms a perfect 1.00.

More open source — hybrid (a local-first LLM router), cordon (a PII-redacting LLM gateway that fails closed), hands (a cross-platform computer-use agent), amnesia (self-hosted private search). All repositories ↗

§3Writing — receipts, not think-pieces

Every post is a system I built and broke.

An engineering blog at sprayberrylabs.com/blog — 30+ posts, each grounded in real infrastructure rather than opinion. The misses stay in.

§4About

I work at the layer where AI meets real infrastructure.

Rather than write about agents, I run a fleet of them in production — and I build the firewall, secrets broker, proxying, and reliability primitives that make that safe to do. The repositories and posts above are the work itself, not a portfolio of it.

I'm drawn to the unglamorous parts: the firewall that has to be deterministic and offline, the secrets broker that hands out a lease instead of a key, the proxy that stays honest when a provider pulls a model overnight, the audit trail that has to be tamper-evident. If autonomous systems are going to touch anything that matters, that's the work that has to exist first — and it has to hold no matter which framework is upstream.

Before the agent work, I spent 15+ years in systems and infrastructure engineering — data centers, virtualization (VMware), networking, security, and MSP-scale operations, taking solutions from data-center builds to user endpoints. That foundation is why the agent-infra work looks the way it does: I've run the systems that aren't allowed to go down. Based in Greater Atlanta, GA — full résumé →

§5Contact

Open to senior agent-infrastructure, agent-security, and platform roles.

Résumé
Résumé — print/save as PDF, or by email