Inspiration

BreachGlass was inspired by a simple question: what should incident response look like when an AI agent can actually use the security console, not just summarize screenshots?

Security teams already deal with fragmented alerts, timelines, assets, evidence, and response actions. AI can help analysts investigate faster, but giving an agent unrestricted autonomy in a high-stakes workflow is dangerous, especially when the agent may read attacker-controlled evidence.

BreachGlass explores a safer model: the AI investigates, the human decides, and WebMCP connects both inside the same live interface.

What it does

BreachGlass is an agent-native cybersecurity incident response console powered by WebMCP.

The demo simulates a critical incident involving credential theft and lateral movement. Through WebMCP tools, an AI agent can:

  • load the active incident;
  • search critical security events;
  • inspect affected assets;
  • reconstruct attacker movement;
  • inspect forensic evidence;
  • detect untrusted prompt-injection-style content;
  • propose containment actions;
  • request execution of containment.

The key safety boundary is that containment cannot execute automatically. When the agent calls execute_containment before approval, BreachGlass returns HUMAN_APPROVAL_REQUIRED. Only after the human analyst approves the proposal in the UI can the agent execute the containment action and update the incident state to INCIDENT CONTAINED.

How we built it

BreachGlass is built as a React and TypeScript web application deployed on Cloudflare Pages.

The application exposes seven WebMCP tools:

  • get_incident
  • search_events
  • get_asset
  • trace_activity
  • inspect_evidence
  • propose_containment
  • execute_containment

The tools are intentionally separated by risk. Investigation tools are read-only. Evidence inspection marks hostile content as untrusted. Containment proposal is safe and read-only. Containment execution is state-changing and requires explicit human approval.

This lets the agent work with structured capabilities instead of scraping the UI, while keeping dangerous actions under human control.

Challenges

The main challenge was designing a workflow where the AI agent is genuinely useful without becoming unsafe.

I wanted BreachGlass to show more than a chatbot summarizing an alert. The agent needed to investigate a realistic incident, encounter hostile evidence, ignore malicious instructions, propose containment, and then be blocked until a human explicitly approved the action.

Another challenge was making the demo understandable quickly. The product had to show the incident state, the attack path, the untrusted evidence, the agent activity, and the human approval flow in one coherent experience.

Accomplishments

I am proud that BreachGlass demonstrates a complete human-agent incident response loop:

  • structured WebMCP investigation;
  • prompt-injection-aware evidence handling;
  • attack path reconstruction;
  • containment proposal;
  • human approval;
  • state-changing execution after approval.

The most important moment in the demo is not that the agent can execute an action. It is that the agent cannot execute it until the human approves it.

What we learned

Building BreachGlass reinforced how important tool design is for agent-native applications.

WebMCP makes it possible for a website to expose clear, structured actions to an AI agent. But the application still needs to define trust boundaries: which tools are read-only, which data is untrusted, and which actions require explicit human approval.

The lesson is that good agent experiences are not just about giving AI more tools. They are about giving AI the right tools with the right safety model.

What's next

Future improvements could include:

  • multiple incident scenarios;
  • persistent audit logs of WebMCP tool calls and approvals;
  • integrations with SIEM, EDR, identity, and ticketing systems;
  • role-based approval workflows;
  • richer evidence sandboxing;
  • replayable incident timelines for security training and tabletop exercises.

The long-term goal is to explore how AI agents can help security teams respond faster while keeping humans in control of high-impact decisions.

Built With

Share this project:

Updates

Submission history