Knox Overview
Knox is the Qoris safety layer for AI workers and developer agents. It checks risky actions before execution, records what happened, and gives teams a way to run autonomous workflows without blindly trusting every tool call. Knox exists because modern agents do real work:- run shell commands
- edit files
- call MCP tools
- read and write memory
- connect to business systems
- schedule background work
- act through subagents
Product Positioning
Knox is the governance moat for Qoris. It helps answer enterprise questions like:- What did the agent try to do?
- Was the action allowed, denied, sanitized, or escalated?
- Which policy matched?
- Did the agent touch secrets, files, MCP tools, or external systems?
- Can a human review risky actions before they execute?
- Can we prove what happened later?
Where Knox Runs
Knox currently exists in two related forms:Qoris Runtime Knox
The built-in safety engine inside Qoris worker containers. It governs shell commands, file writes, memory writes, subagent attribution, and runtime audit.
Knox Claude Code Plugin
A standalone Claude Code plugin that uses hooks and a CLI to protect developer machines from risky agent actions.
What Knox Checks
Knox focuses on action safety rather than only content moderation. Common checks include:- dangerous shell commands
- destructive file operations
- writes to protected config files
- suspicious script content before execution
- inline code execution patterns
- secret access paired with network egress
- attempts to disable Knox or mutate its config
- prompt injection in user input or MCP tool input
- scheduled or autonomous task creation
Knox And MCP
MCP tools make agents more useful by giving them access to external systems. They also increase the blast radius of mistakes. Knox treats MCP as part of the action surface:- MCP tool inputs can be inspected
- risky external actions can be blocked or escalated
- tool calls can be audited
- per-tool policy can be layered over the MCP connection
Knox And Human Approval
Knox and approvals are complementary. Knox decides whether an action is mechanically safe enough to continue. Human approval handles business judgment for actions that may be valid but sensitive. Examples:- reading public documentation: allow and audit
- drafting an external email: allow and audit
- sending the external email: require approval
- creating an invoice: require approval
- reading a secret and sending it over the network: block
- changing Knox settings to disable hooks: hard block
Why It Matters
Without Knox, every connected tool becomes a trust problem. With Knox, Qoris can say:AI workers can act, but every action is governed, policy-checked, and auditable.That is the difference between an agent demo and an enterprise AI worker platform.
