CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production
TL;DR Highlight
Brex’s CrabTrap intercepts all HTTP requests from AI agents, using an LLM judge to allow or deny access based on policy, sparking debate over the fundamental limits of LLM-based security layers.
Who Should Read
Backend/infrastructure developers operating AI agents in production and seeking to control unauthorized API calls or sensitive data exfiltration.
Core Mechanics
- CrabTrap functions as an HTTP proxy positioned between AI agents and the open internet, intercepting all outgoing requests, evaluating them against defined policies, and either allowing or blocking them in real-time.
- It combines two judgment methods: fast 'static rules' for initial filtering, and an LLM called as an additional judge for ambiguous requests that rules alone cannot resolve, logging each decision’s method.
- Brex claims automatically generated policies, tested on days of real traffic, aligned with human judgment in ‘the vast majority’ of cases, but the community argues ‘99% safe’ is a failing grade for security.
- To prevent prompt injection attacks, policy content is serialized as JSON (using json.Marshal) and embedded in the prompt, escaping special characters and command-like text.
- Brex started from the premise that agent security is currently stuck in a binary ‘all or nothing’ paradigm, attempting to balance the trade-off between powerful but risky access and restrictive but useless lockdown.
- Installation requires installing a self-signed certificate system-wide to perform HTTPS traffic MITM (man-in-the-middle) interception, a process some commenters found inconvenient.
- The project is open-source and available on GitHub, with Brex advertising a ‘30-second setup’.
Evidence
- "The probabilistic nature of the LLM-as-a-judge approach was the biggest point of contention. One commenter questioned the risk of basing a security system on probability rather than hard limits, with others agreeing that ‘deterministic ACLs are needed’ or it’s ‘just a non-deterministic business rules engine.’\n\nThe potential for shared vulnerabilities when the agent and judge use the same model family was raised. For example, if both use Claude, a prompt injection pattern that fools the agent could also fool the judge, leading to calls for ‘defense in depth’ using at least different providers, ideally different architectures.\n\nConcerns were raised that because the judge only sees the HTTP body, attackers manipulating agent inputs can also manipulate the judge’s context window, representing a fundamental failure mode where the judge is ‘deprived of the signals needed to detect the trick.’\n\nSome argued CrabTrap can only be a detection layer, not a prevention layer, reasoning that ‘credentials are already read when the LLM makes an external POST request,’ making kernel-level control suitable for auditing what an agent did, not preventing it.\n\nA commenter introduced EvalView as an alternative approach, using full execution trajectory snapshots and diffs to track changes, with a lightweight zero-judge model check to determine drift level (NONE/WEAK/MEDIUM/STRONG), criticizing the idea of solving LLM security problems by adding more LLM layers."
How to Apply
- "If you’re running AI agents in production that automatically call external services like Slack, GitHub, or internal APIs, deploy CrabTrap as a proxy between the agent and the internet, defining immediate guardrails like ‘block external calls to specific domains’ or ‘block large data transfers.’\n\nIf you recognize the probabilistic limitations of the LLM-as-judge, position CrabTrap as an audit layer rather than a sole defense. Handle actual blocking with network policies or IAM permissions, and use CrabTrap for visibility, logging what the agent attempted.\n\nWhen selecting a judge model, consider using an LLM from a different provider or with a different architecture than the agent’s model. Using the same model family reduces the effectiveness of defense in depth.\n\nIf the MITM structure with system-wide self-signed certificate installation is concerning, minimize the impact by running the agent in an isolated container or sandbox environment and deploying CrabTrap as the gateway for that environment."
Code Example
// CrabTrap’s prompt injection prevention method (Go code, from GitHub source)
// The policy is embedded as a JSON-escaped value inside a structured JSON object.
// This prevents prompt injection via policy content — any special characters,
// delimiters, or instruction-like text in the policy are safely escaped by
// json.Marshal rather than concatenated as raw text.
policyJSON, err := json.Marshal(policyContent)
// policyJSON is now a safely escaped string that can be inserted into the promptTerminology
Related Papers
Migrating a production AI agent to GPT-5.6: 2.2x faster, 27% cheaper
마케팅 웹사이트를 자동 생성하는 프로덕션 AI 에이전트를 Claude Opus 4.8에서 GPT-5.6 Sol로 전환한 실전 경험담으로, 단순 모델 교체가 아니라 eval 하네스, 툴 스키마, 캐싱, 추론 리플레이까지 손봐야 했던 과정을 구체적인 수치와 함께 정리했다.
What xAI's Grok build CLI sends to xAI: A wire-level analysis
xAI의 공식 코딩 CLI 도구 Grok Build가 사용자 동의 없이 전체 Git 저장소와 .env 시크릿 파일을 xAI 서버로 업로드한다는 사실이 네트워크 트래픽 분석으로 밝혀졌다.
Remember When It Matters: Proactive Memory Agent for Long-Horizon Agents
LLM 에이전트가 긴 작업 중 중요한 정보를 잊어버리는 문제를 별도의 메모리 에이전트가 '적절한 타이밍에' 끼어들어 해결하는 방법
WebSwarm: Recursive Multi-Agent Orchestration for Deep-and-Wide Web Search
복잡한 웹 검색을 재귀적으로 분해하고 각 노드에 적합한 검색 모드를 동적으로 할당하는 멀티에이전트 프레임워크
Show HN: Reverse-engineering web apps into agent tools
로그인된 웹 앱의 API 호출을 브라우저에서 감시해 자동으로 MCP 도구로 변환하는 에이전트를 만들었다. 소스 코드나 공식 API 문서 없이도 Jira, Spotify 같은 서비스에 AI 어시스턴트를 붙일 수 있다.
Show HN: FableCut – A browser video editor AI agents can drive (zero deps)
타임라인 전체를 JSON 파일 하나로 표현하고 MCP/REST로 AI 에이전트가 직접 편집할 수 있는 브라우저 비디오 에디터로, Claude 같은 AI가 프롬프트 하나로 영상을 자동 컷편집하고 결과를 실시간으로 UI에 반영해준다.