Two banners fly here. Own Your Agent Security — govern what your agents are allowed to do. Own Your Stack — own the AI infrastructure they run on instead of renting it by the token. Related, but not the same question — and each gets its own answer.
Don't trust agents by default. A firewall for every agent tool call, a supply-chain gate for every skill, a governed browser between the agent and the open web, and a trajectory monitor watching the whole sequence — one layered defense, running in production here.
redstamp · truecopy compose into one layered defense → agent-security-stack — vet the tool, contain the call. plumbline watches the whole trajectory from out of band.
One subscription. Your box. Your terms. You were sold a meter — intelligence rented by the token, your data through someone else's pipes, your tools on someone else's roadmap and someone else's pricing meeting. I'm building the opposite: a stack you actually own. The open tools are the door; a real autonomous studio running in production is the proof — the unfinished parts included.
More of the stack → ownyourstack.sprayberrylabs.com
Sprayberry Labs is the software studio with one human on staff — and a lab in the literal sense: every claim above traces to a merged PR, a release, or a measured incident. The supply chain is scored in public, too: dario holds a 9.4/10 OpenSSF Scorecard and a 100% OpenSSF Best Practices badge — releases signed and SLSA-attested, npm published tokenless from CI. And not all of it is my own code: a Windows long-path fix I sent upstream to huggingface_hub — the client library the Hugging Face stack is built on — was merged by the maintainer on the first pass. Some of the write-ups:
- We scanned the marketplace that started the poisoned-skills panic — all 66,541 ClawHub skills poison-scanned with truecopy: zero confirmed malicious, 813 deterministic alarms, every one checked and mapped
- The leaderboard I refused to build — why an agent-firewall leaderboard would be a category error; a threat-model map instead, with redstamp's own benchmark numbers shown, misses included
- Auditing the skills supply chain — truecopy run across 2,019 published Claude skills: what a real marketplace audit finds, and doesn't
- Zero raw credentials — migrating a live agent fleet from 132 inherited environment keys to strongroom leases, one seam at a time
- An injection firewall for the agentic browser — why the lethal trifecta is structural, and how fieldpass gates it
- A self-healing release pipeline — how dario ships, health-gates, and rolls itself back
- Redstamp governing third-party frameworks — CrewAI · LangGraph · OpenAI Agents SDK · AutoGen, each with a runnable public example in askalf/redstamp
Full engineering log → sprayberrylabs.com/blog
It's hard, and it's not finished — that's the point. The value isn't a demo; it's the scars from running agents in production for real. I write down what actually happens.
I'm Thomas Sprayberry — fifteen-plus years of engineering, from solo founders to Fortune 500. I run Sprayberry Labs, the software studio with one human on staff: askalf — the AI operation built from the tools above — ships the code, reviews the pull requests, verifies the findings, and watches production. I architect, review, and sign everything that leaves the shop.
Portfolio → thomas.sprayberrylabs.com
Own Your Stack · Own Your Agent Security · the operation · sprayberrylabs.com · @ask_alf · hello@sprayberrylabs.com






