ax-ai-agent-mvp: Project AX and the Architecture of the Fireproof Agent
How a Trust Zone proxy and a 34k-line audit-first codebase solved the security crisis that nearly killed the autonomous assistant.
- The Trust Zone proxy isolates the agent in a network-free container to ensure every outbound request is audited and sanitized.
- Project AX limits its codebase to 34,000 lines of TypeScript to remain small enough for a single developer to audit.
- Strict Provider Contracts replace raw text outputs with type-safe functional signatures to prevent unvalidated API execution.
- The architecture prioritizes a minimal security surface over the sprawling feature sets found in monolithic agent frameworks.
The Air-Gapped Mind
Most articles about AI agents lead with their capabilities. Project AX is defined by its constraints. In the wake of high-profile security failures in autonomous systems, AX introduces the Trust Zone proxy. The agent itself lives in a container with zero direct network access.
Instead of allowing an LLM to freely browse the web or execute scripts, AX forces every outbound request through a host-level gatekeeper. This proxy audits, sanitizes, and approves every action before it reaches the outside world. It is the boring security engineering that finally makes autonomous agents safe for the paranoid.
A Reaction to the Bloat
The autonomous agent ecosystem of the mid-2020s was defined by massive, sprawling frameworks. Projects like OpenClaw proved the utility of multi-channel agents but suffered from catastrophic security flaws due to their massive, unauditable codebases. Bloat had become a vulnerability.
This realization sparked a fracture in the developer community. Some builders abandoned the always-on assistant model entirely in favor of single-purpose command-line tools.
I built Axe because I got tired of every AI tool trying to be a chatbot. Most frameworks want a long-lived session with a massive context window doing everything at once. That's expensive, slow, and fragile.
Project AX took a different path. It maintained the dream of an always-on personal assistant but rebuilt it from scratch in under 35,000 lines of TypeScript. The goal was simple: an architecture that a single developer could audit in a long weekend.
The Provider Contract
To prevent hallucinations and secure tool execution, AX treats LLMs as interchangeable commodities via a strict Provider Contract. It replaces unpredictable prompt engineering with type-safe functional signatures.
export interface AxSignature {
input: { query: string; context: string };
output: { action: string; parameters: Record<string, unknown> };
rules: string[];
}
By enforcing these signatures, the agent cannot output raw, unvalidated text to a sensitive API. Every response is coerced into a predefined schema, severely limiting the blast radius of a compromised or hallucinating model.
The Minimalist Benchmark
The landscape of autonomous agents is now defined by these divergent philosophies. The table below illustrates how AX sits between the raw minimalism of CLI tools and the heavy orchestration of legacy frameworks.
| Feature | AX | Axe | OpenClaw |
|---|---|---|---|
| Architecture | Trust Zone Proxy | Single Unix Binary | Monolithic OS Access |
| Primary Interface | Always-on Assistant | CLI / Cron | Chat GUI |
| Codebase Size | ~34k LOC | ~12MB Binary | 170k+ LOC |
| Network Access | Strictly Proxied | Host Level | Unrestricted |