cloud.deploy
A write-capable deployment tool is now callable by release-triage.
agents/release.yaml:42AgentMordor turns scattered tools, identities, data access, and approval rules into one evidence-backed map. Follow the path from untrusted input to a real-world action before an agent reaches production.
This blog page does not scan configurations, import reports, or run the AgentMordor CLI. The interface below uses fixed synthetic data only to explain the standalone product.
Select an access path, inspect its evidence, then switch to Changes or Controls. This promotional preview uses fixed synthetic data and never reads a local file or touches a real environment.
A write-capable deployment tool is now callable by release-triage.
agents/release.yaml:42The agent resolves a production role instead of the previous staging identity.
infra/agent-role.tf:18Network access changed from two named endpoints to a wildcard destination.
policies/egress.yaml:11Publishing a research report now requires a security-reviewers decision.
agents/research.yaml:67One new path joins untrusted content to a production write operation without human approval.
agentmordor diff --fail-on new-critical-pathProduct functionality lives in the separate AgentMordor project, not in this blog.
AgentMordor does not guess whether a prompt sounds dangerous. It follows configured access until it reaches a file, secret, API, cloud role, or real-world action—and shows the evidence used for every connection.
Start with explicit MCP JSON inputs, then add host-specific adapters without silently searching the operator's home directory.
v0.1 · explicit MCP JSON inputTurn isolated permissions into readable end-to-end paths, including where input comes from and what can change.
Input → agent → identity → actionAttach a source file, line, confidence, and plain-language reason to every inferred connection.
No unexplained risk scoresStore a safe baseline and reveal only the new authority introduced by a pull request or configuration change.
JSON · SARIF · HTMLRead-only MCP JSON parser, deterministic findings, text/JSON reports, redaction tests, and synthetic fixtures.
Baseline comparison, policy thresholds, SARIF output, CI annotations.
Safe deny tests, approval validation, framework mappings, signed evidence.