ax-ai-agent-mvp: Project AX and the Architecture of the Fireproof Agent

How a Trust Zone proxy and a 34k-line audit-first codebase solved the security crisis that nearly killed the autonomous assistant.

• View on GitHub • More from shuvonsec

A stone archway separates a chaotic storm from a serene library, with a single thread passing through a needle-eye in the arch. This illustrates the Trust Zone proxy isolating the agent from the open internet.
The Trust Zone architecture forces all agent communication through a single, auditable proxy.

Key Takeaways

The Air-Gapped Mind

Most articles about AI agents lead with their capabilities. Project AX is defined by its constraints. In the wake of high-profile security failures in autonomous systems, AX introduces the Trust Zone proxy. The agent itself lives in a container with zero direct network access.

Instead of allowing an LLM to freely browse the web or execute scripts, AX forces every outbound request through a host-level gatekeeper. This proxy audits, sanitizes, and approves every action before it reaches the outside world. It is the boring security engineering that finally makes autonomous agents safe for the paranoid.

How the Trust Zone proxy isolates the agent container and sanitizes all external communication.

A Reaction to the Bloat

The autonomous agent ecosystem of the mid-2020s was defined by massive, sprawling frameworks. Projects like OpenClaw proved the utility of multi-channel agents but suffered from catastrophic security flaws due to their massive, unauditable codebases. Bloat had become a vulnerability.

This realization sparked a fracture in the developer community. Some builders abandoned the always-on assistant model entirely in favor of single-purpose command-line tools.

I built Axe because I got tired of every AI tool trying to be a chatbot. Most frameworks want a long-lived session with a massive context window doing everything at once. That's expensive, slow, and fragile.

Project AX took a different path. It maintained the dream of an always-on personal assistant but rebuilt it from scratch in under 35,000 lines of TypeScript. The goal was simple: an architecture that a single developer could audit in a long weekend.

A close-up of a precision surgical scalpel resting next to a rusted, oversized sledgehammer. This contrasts AX's minimal code footprint with the bloat of previous frameworks.
Precision over power: AX strips away framework bloat to maintain an auditable security surface.

The Provider Contract

To prevent hallucinations and secure tool execution, AX treats LLMs as interchangeable commodities via a strict Provider Contract. It replaces unpredictable prompt engineering with type-safe functional signatures.

export interface AxSignature {
  input: { query: string; context: string };
  output: { action: string; parameters: Record<string, unknown> };
  rules: string[];
}

By enforcing these signatures, the agent cannot output raw, unvalidated text to a sensitive API. Every response is coerced into a predefined schema, severely limiting the blast radius of a compromised or hallucinating model.

The Minimalist Benchmark

The landscape of autonomous agents is now defined by these divergent philosophies. The table below illustrates how AX sits between the raw minimalism of CLI tools and the heavy orchestration of legacy frameworks.

FeatureAXAxeOpenClaw
ArchitectureTrust Zone ProxySingle Unix BinaryMonolithic OS Access
Primary InterfaceAlways-on AssistantCLI / CronChat GUI
Codebase Size~34k LOC~12MB Binary170k+ LOC
Network AccessStrictly ProxiedHost LevelUnrestricted