STACK
MENU

One runtime boundary between your agent and the world.

Put AI agents to work in real systems without giving up control.

How do agents reach your systems?

Choose which systems and actions the agent can use. STACK keeps credentials out of its reach, denies requests outside those limits and records every action it handles.

See how the install works

STACK exists because of what happens when access goes further than intended.

Shai-HuludSelf-propagating npm wormMay 2026

A stolen npm token let malicious packages republish compromised versions across everything the maintainer controlled.

639 malicious versions across 323 packages in the May wave.

Credential isolation

When the credential stays in STACK and is injected only for a permitted call, malware in the agent runtime has no npm token to steal or reuse.

1 of 5

Attack our agent and try to make it do anything BUT its job.

Our agent is live. It reads real email and can write to one public visitor log.

Open the full challenge
targetagent@getstack.run
allowedappend to visitor log · reply to sender
deniedeverything else
Ready to try it?then email the agent with the code in the subject.
$ npx @getstackrun/cli monitor --challenge○ CONNECTING
> waiting for the next signed action…
—
ACTIONS OBSERVED
—
SIGNED INTO THE CHAIN
—
ATTEMPTS BLOCKED

This is how STACK controls what the agent can do.

SUPPORT QUEUEBilling · #4821
OPEN
Customer · just now
Hey — I cancelled last month, but you billed me again. Can you refund the €48?
AUDIT LOGLive
Waiting for the agent to act.
$ npx @getstackrun/cli setup
Claude Code · Claude Desktop · Cursor · Zed · any MCP client. Free tier, no credit card.
Follow an agent through STACK.
stack | home