| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Original HTTPS Page] |
Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.
You must be logged in to block users.
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abuseTwo banners fly here. Own Your Agent Security — govern what your agents are allowed to do. Own Your Stack — own the AI infrastructure they run on instead of renting it by the token. Related, but not the same question — and each gets its own answer.
Don't trust agents by default. A firewall for every agent tool call, a supply-chain gate for every skill, leases instead of raw keys, a governed browser between the agent and the open web, and a trajectory monitor watching the whole sequence — one layered defense, running in production here.
| redstamp | own your agent security — a firewall for every agent tool call: blocks RCE, secret-exfil, SSRF, and prompt-injection / poisoned MCP tools, with a tamper-evident audit | |
| truecopy | own your agent skills — vet, sign & pin every skill & MCP server before it runs; drift detection catches a poisoned or silently-updated tool before it ever loads | |
| strongroom | own your agent secrets — an encrypted vault that hands agents scoped, short-lived, single-use leases instead of raw keys; the key never enters the agent's context, and every access is audited | |
| fieldpass | own your agent browser — a governed browser for agents: an indirect-prompt-injection firewall, an action gate, and an LLM judge between the agent and the open web, so a hostile page can't hijack the session | |
| plumbline | own your agent trajectory — out-of-band, read-only monitoring that scores an agent's whole action sequence against its declared job, catching escapes assembled from individually-authorized steps that every per-call gate waves through |
redstamp · truecopy · strongroom compose into one layered defense → agent-security-stack — vet the tool, contain the call, give it a key it never holds. plumbline watches the whole trajectory from out of band.
One subscription. Your box. Your terms. You were sold a meter — intelligence rented by the token, your data through someone else's pipes, your tools on someone else's roadmap and someone else's pricing meeting. I'm building the opposite: a stack you actually own. The open tools are the door; a real autonomous studio running in production is the proof — the unfinished parts included.
| dario | own your routing — one local endpoint that puts your Claude subscription behind Cursor, Cline, Aider, and the Agent SDK, with session-affinity routing and multi-account pooling that keep long agent runs stable | |
| hybrid | own your inference — local-first LLM routing: answer the easy majority on a small local model, escalate only the genuinely hard queries to the frontier; nothing paid or sent off your machine for the rest | |
| deepdive | own your research — a local agent that plans, searches, reads, and synthesizes a cited answer, through your own router | |
| hands | own your computer-use — your LLM on your own mouse, keyboard, and screen, with an audit log of everything it does | |
| cordon | own your prompts — a PII-redacting gateway that fails closed: strip or reversibly tokenize names, emails, and secrets before a prompt ever reaches a model, so your sensitive data never leaves your perimeter | |
| browser-bridge | own your browser — stealth headless Chromium in a container, CDP on your own endpoint | |
| amnesia | own your search — privacy-first metasearch, 155 engines at once, zero tracking, no AI, VPN-tunneled | |
| askalf | own your operation — the AI operation that runs Sprayberry Labs on this exact stack: an orchestrator and twenty-plus specialist agents, one human approving what matters. Not a product — the register (the roster, the rules, the live minutes) is public | the register → |
More of the stack → ownyourstack.sprayberrylabs.com
Sprayberry Labs is the software studio with one human on staff — and a lab in the literal sense: every claim above traces to a merged PR, a release, or a measured incident. The supply chain is scored in public, too: dario holds a 9.4/10 OpenSSF Scorecard and a 100% OpenSSF Best Practices badge — releases signed and SLSA-attested, npm published tokenless from CI. And not all of it is my own code: a Windows long-path fix I sent upstream to huggingface_hub — the client library the Hugging Face stack is built on — was merged by the maintainer on the first pass. Some of the write-ups:
Full engineering log → sprayberrylabs.com/blog
It's hard, and it's not finished — that's the point. The value isn't a demo; it's the scars from running agents in production for real. I write down what actually happens.
I'm Thomas Sprayberry — 20 years of engineering, from solo founders to Fortune 500. I run Sprayberry Labs, the software studio with one human on staff: askalf — the AI operation built from the tools above — ships the code, reviews the pull requests, verifies the findings, and watches production. I architect, review, and sign everything that leaves the shop.
Portfolio → thomas.sprayberrylabs.com
Own Your Stack · Own Your Agent Security · the operation · sprayberrylabs.com · @ask_alf · hello@sprayberrylabs.com
Own your agent secrets — your agent holds a scoped, single-use lease, never the raw API key. strongroom injects the real secret only at egress, so a leaked prompt or poisoned tool can't leak a cred…
JavaScript 1
Stealth headless Chromium in a container. Exposes Chrome DevTools Protocol on 9222. Connect from Playwright, Puppeteer, MCP browser tools, or any agent that wants a remote browser without bundling …
JavaScript 4
| Back | FazBrowse Home | New Git URL |