How this started
It started with a bad day. An AI coding agent I was running deleted part of my own production environment — no warning, no confirmation, just gone. It wasn't malicious. It was just doing what it thought I asked, with far more authority than it should ever have had.
I built Thuban Shield to fix my own problem: something local, real-time, that would sit between the agent and the machine and say no when it mattered. I open-sourced it because I figured other people were about to learn the same lesson the hard way.
What I didn't expect was how fast this became an actual discipline. Every AI coding agent is a privileged insider. It reads your secrets, writes your files, runs your shell. Almost nobody was treating it that way. The more I looked, the more it was clear this wasn't a side project — it was a gap that needed an independent safety layer, not another feature bolted onto the tools doing the building.
So that's what I'm building now: Thuban Shield to enforce, Thuban Forge to learn from what's actually happening in the wild, Thuban Crucible to prove the defences hold up, and Thuban Blackbox to explain exactly what happened when something goes wrong. All of it independent of the agents and platforms it watches — on purpose.