Bartholomew Keystone — Control What Your AI Agent Can Do
Give your AI agent a signed permission slip. It can only do what you said it could.
What It Does
Right now, AI coding agents work with all-or-nothing access. If you give Cursor or Copilot permission to run code, it can run anything — including things you didn't intend.
Keystone fixes that. You issue a cryptographically signed passkey that defines exactly what the agent can and can't do. Then Keystone enforces those limits on every action the agent attempts.
Guard vs. Keystone — Start Here
Guard
Keystone (this extension)
What it does
Automatically blocks known-dangerous code and credential leaks
Lets you define custom rules — what files, commands, and actions are allowed