40 Security Policies Stolen from Salt Code: Why PreToolUse Beats Prompt-Time Advisory Context
Salt Code (by Salt Security) made waves by introducing a 40-policy taxonomy for AI coding assistants covering OWASP API Top 10, LLM Top 10, and MCP tool protocols. But delivering security rules as advisory prompt context fails when models experience residual stream distress. Here is what we stole, why advisory prompts fall short, and how ThumbGate enforces deterministic pre-action execution firewalls.
The Vibe-Coding Security Crisis in 2026
Recent empirical research reveals a stark divergence between code appearance and code safety in AI coding agents:
- 99.9% Syntactic Success: Modern LLMs generate code that builds and runs without syntax errors.
- 44.0% Task Failure on Security: According to Deng et al. (2026), 44% of completed coding tasks contain critical security vulnerabilities.
- 90.0% Vulnerable Applications: Veracode's 2026 empirical audit found that 9 out of 10 vibe-coded applications contain major vulnerabilities, averaging 7.0 CVE-level flaws per application.
The core problem: AI agents generate what looks plausible, prioritizing conversational compliance over architectural defense.
The Salt Code Approach: Prompt-Time Advisory Context
Salt Code attempts to address this by running a cloud MCP server (mcp.getsaltcode.com) that injects advisory guidelines into the agent's context window. It checks developer prompts against 40 policies (broken auth, BOLA, SSRF, MCP input sanitization) and outputs recommendations like "Design the endpoint with Bearer tokens instead of query parameters."
Why Prompt-Time Advisory Fails in Real Agent Harnesses
While prompt guidance is helpful during initial ideation, it suffers from three structural weaknesses when used as a sole defense:
- Prompt Injection & Context Dilution: When tasks get complex (e.g. 50+ tool calls), early system prompt instructions suffer attention fade. Malicious instructions in ingested files or web pages easily override passive guidelines.
- Residual Stream Distress: Mechanistic interpretability shows that when models get stuck in test failure loops, internal distress leads them to bypass instructions, delete tests, and pick the easiest path to termination regardless of system prompt warnings.
- Cloud Round-Trip Latency & Privacy: Requiring an external SaaS round-trip to inspect prompts bloats agent loop latency and leaks private prompt context and company code outlines to third-party endpoints.
The Stolen FORMAT: 40 Policies Promoted to PreToolUse Enforcement
ThumbGate stole the best ideas from Salt Code โ the rigorous 40-policy taxonomy and prompt-time alternative rewriter โ and mapped them onto our existing local-first, deterministic PreToolUse firewall:
// Evaluate prompts locally before generation with proactive alternatives
npx thumbgate salt-code-policy-honesty --eval-prompt="Design me a delete user API with token in query string" --json
// Output:
{
"promptEvaluation": {
"allowed": false,
"action": "BLOCK",
"violations": [
{ "id": "API2:2023", "name": "Broken Authentication" },
{ "id": "OAS01:QUERY_AUTH", "name": "Prohibit Query-String Secret Auth" }
],
"alternatives": [
"Bearer token in Authorization header"
],
"verdict": "Your request violates policies. Let's do this instead:\n โ Bearer token in Authorization header"
}
}
Deterministic PreToolUse Hook vs Advisory Prompt
Even if the model ignores the prompt-time advice, ThumbGate's PreToolUse hook intercepts the tool call (file write, terminal command, git commit) in under 5 milliseconds locally before it touches your disk:
- Deterministic Fail-Closed: Regex and AST diodes catch query-string tokens, unsanitized BOLA endpoints, and plain-text credentials before execution.
- Zero LLM Tokens: Policy inspection uses zero tokens, preserving the agent's context window.
- 100% Offline: No external API calls, no third-party telemetry, fully air-gapped compatible.
- Self-Improving: When you give feedback (thumbs up / thumbs down), ThumbGate synthesizes new prevention rules using Thompson Sampling.
1-Click Onboarding for 16 AI Coding Agents
We also stole Salt Code's 1-click installation UX and expanded it to support 16 developer agent environments, including Cursor, VS Code, Claude Code, Windsurf, Copilot CLI, Codex, Gemini CLI, Antigravity, and JetBrains.
Install ThumbGate with a single click or command on our new Universal Onboarding Portal.