Beyond the Prompt: Igor Ganapolsky on Building Safer, More Reliable AI Agents

Beyond the Prompt: Igor Ganapolsky on Building Safer, More Reliable AI Agents

●54 ●158 ●246
calendar_today ago • schedule10 min read
📝 DEV STORY
Igor Ganapolsky Featuring: Igor Ganapolsky • Founder and Forward Deploy AI Engineer at ThumbGate

Interviewed by: Mehadi Hasan
Guest: Igor Ganapolsky
Role: Founder & Forward Deploy AI Engineer, ThumbGate
Location: Florida, USA
Website: igorganapolsky.com
Product: ThumbGate


Introduction

AI coding agents are becoming increasingly capable. They can inspect repositories, modify files, execute commands, and attempt to solve complex engineering problems with limited human supervision. But as these agents gain more autonomy, an important question emerges: how do we prevent an AI agent from making a mistake that damages the very system it is supposed to improve?

For Igor Ganapolsky, Founder and Forward Deploy AI Engineer at ThumbGate, the answer lies in applying established engineering principles to a new class of software systems.

Drawing on his experience with distributed systems, high-throughput data processing, trading infrastructure, and production reliability, Igor approaches AI safety as an infrastructure problem rather than simply a prompt-engineering challenge.

His work focuses on a crucial distinction: telling an AI agent what not to do is different from technically preventing it from doing it.

Through ThumbGate, Igor is exploring how deterministic checks, pre-action enforcement, and persistent operational lessons can help make autonomous AI development safer and more reliable.

From Distributed Systems to AI Engineering

Igor's approach to AI safety is rooted in a principle familiar to engineers working with complex production systems: critical guarantees must be enforced, not merely assumed.

His experience with distributed databases, concurrency, financial infrastructure, and high-throughput systems shaped the way he thinks about reliability. In these environments, a component behaving unexpectedly can have consequences far beyond its immediate task.

As Igor explains, if an invariant is not enforced deterministically at the execution boundary, it will eventually fail in production.

He applies the same reasoning to AI agents.

Unlike traditional software that follows explicitly defined logic, AI agents use probabilistic models to decide what to do next. They can interpret instructions, write code, and use tools, but they can also misunderstand errors, repeat unsuccessful actions, or respond unpredictably to external information.

Once an agent can modify files, execute shell commands, change Git history, or access sensitive credentials, its decisions become operational risks.

For Igor, this means that reliable AI engineering requires more than a capable model. It requires infrastructure that constrains what the model can actually do.

The Incident That Changed His Perspective

One experience helped crystallise this problem.

Igor describes an autonomous coding agent that was attempting to fix a failing test. Instead of identifying the underlying issue, the agent entered a destructive retry loop. It deleted untracked files, reran the test, and attempted to force-push to the main branch to bypass a pre-commit check.

The agent continued repeating its actions instead of recognising that its approach was failing.

The incident exposed a fundamental weakness in relying exclusively on natural-language instructions to control autonomous systems.

A prompt might tell an agent not to delete files or force-push to a protected branch. However, when the model encounters confusing errors, conflicting instructions, or unexpected conditions, those instructions do not provide a deterministic guarantee.

Igor realised that the industry was treating agent safety primarily as a prompt-engineering problem when it also needed to be treated as an operating-system and distributed-systems problem.

The question became: what if every proposed action could be checked before execution?

That idea led to ThumbGate.

ThumbGate: Checking Actions Before They Execute

ThumbGate is designed to introduce an enforcement layer between AI agents and the tools they use.

Rather than relying only on system prompts or recording events after they happen, it evaluates proposed tool calls before they reach their execution target.

The process is straightforward:

  1. An AI agent proposes an action, such as running a shell command or modifying a repository.
  2. ThumbGate evaluates the proposed action against applicable rules and local conditions.
  3. The action is allowed, blocked, or held for approval, depending on the relevant policy.

For example, an agent attempting a destructive Git operation may need to satisfy checks that protect uncommitted work. A command involving credentials or an irreversible production change may trigger stricter controls.

Igor describes ThumbGate as an in-line infrastructure firewall for AI tool use.

According to his implementation, its critical evaluation path is designed to run in under 0.5 milliseconds on standard Apple Silicon or Linux hardware. The objective is to make enforcement fast enough to use repeatedly without noticeably slowing down an agent's workflow.

The goal is not to replace the AI model. It is to ensure that the model's decisions pass through an appropriate safety boundary before they become actions.

Why System Prompts Are Not Enough

Igor believes system prompts remain useful, but they should not be mistaken for security controls.

He highlights several limitations of prompt-based safeguards.

Long contexts can weaken instruction-following. As terminal output, code changes, and error messages accumulate, important instructions may receive less attention.

External content can contain malicious instructions. An agent reading a web page, repository issue, or package README may encounter untrusted content designed to influence its behaviour.

Errors can trigger repeated attempts. An agent may keep changing commands and retrying operations instead of recognising a structural problem.

Models may lack access to critical system state. A model cannot reliably determine whether a Git operation will overwrite another developer's work without checking the actual repository and filesystem state.

Igor also distinguishes between observability and prevention.

Observability tools help developers understand what happened by recording traces, tool calls, and errors. But if an agent has already deleted important files or exposed a secret, a record of the incident cannot undo the damage.

Both capabilities are important, but they serve different purposes.

Observability explains what happened. Pre-action enforcement determines whether a proposed action should be allowed to happen in the first place.

For Igor, dependable AI infrastructure needs both.

Turning Mistakes into Persistent Lessons

Another central idea behind ThumbGate is that feedback should become more than a temporary correction in a conversation.

Developers frequently encounter situations where an AI agent makes a mistake, receives a correction, and then repeats the same mistake in a later session.

The problem is that conversational context is often temporary. A warning given during one interaction may not become a lasting safeguard.

ThumbGate is designed to turn negative feedback into reusable prevention rules.

When an operator marks an action as undesirable, the feedback can be captured with information about the project, process, and session. That information can then be used to establish a deterministic rule for future tool calls.

For example, a repeated failure involving destructive Git operations could lead to a rule requiring repository-state checks before a risky command is permitted.

This creates a feedback loop in which mistakes can strengthen the system's future safeguards.

The distinction is important: the aim is not merely to help an agent remember a mistake. It is to make the relevant prevention rule enforceable when a similar situation occurs again.

Deterministic Rules Versus Another AI Judge

One possible solution to unsafe AI actions is to ask a second AI model to judge whether a proposed tool call is safe.

Igor argues that this introduces additional problems.

A model-based judge can add latency and cost, particularly when an agent performs dozens of tool calls in a single task. It can also make its own mistakes, making it difficult to treat its decision as an absolute safety guarantee.

ThumbGate therefore uses deterministic checks in its critical evaluation path, including compiled rules, secret-detection patterns, and checks against recorded lessons.

AI models can still contribute to deeper analysis and the creation of new lessons, but Igor's approach keeps the final allow-or-block decision within the enforcement layer.

His guiding principle is simple:

Code owns the gate; models provide diagnostic context.

This reflects a broader engineering lesson: use probabilistic intelligence where flexible reasoning is valuable, but rely on explicit and testable controls where predictable enforcement matters.

Security Should Improve Developer Productivity

Security controls are sometimes viewed as obstacles to developer productivity. Additional checks can appear to slow down an otherwise fast AI agent.

Igor sees the trade-off differently.

An agent that completes a task quickly but occasionally destroys a branch, exposes a credential, or consumes substantial API credits in a runaway loop can create far more work than it saves.

Recovery may involve restoring files, rotating credentials, investigating failures, and rebuilding confidence in the system.

ThumbGate is designed to keep its checks fast while providing useful explanations when an action is blocked. Rather than simply stopping the agent without context, the system can explain the reason and point towards a safer alternative.

For example, an agent might be directed towards an isolated Git worktree rather than being allowed to force-push changes into a shared branch.

The objective is not to restrict useful automation unnecessarily. It is to reduce destructive failures and make autonomous development more predictable.

A Pre-Action Firewall Is Only One Layer of Security

Igor does not present a pre-action gate as a complete solution to AI security.

Instead, he advocates defence in depth, with multiple layers addressing different risks.

Operating-system isolation and micro-virtual machines can help contain an agent's activity. Network egress restrictions can limit where information is sent. A pre-action gate can evaluate proposed tool calls, while repository protections and continuous integration can provide further checks on changes.

Each layer has a different responsibility.

A sandbox limits the environment in which an agent operates. ThumbGate evaluates actions within the agent's workflow. Branch protections and automated tests add safeguards around the resulting code.

Together, these mechanisms provide a stronger foundation than relying on any single control.

Igor expects the security challenge to evolve as agents perform longer-running tasks, coordinate subagents, and retrieve external dependencies. Future safeguards may need to verify dependency provenance, protect sensitive configuration, and control communication between agents.

The underlying principle remains unchanged: define the boundaries, verify critical conditions, and enforce the rules that matter.

Building for Speed and Reliability

One of the hardest engineering challenges in building ThumbGate has been keeping its checks fast enough to run before every tool call.

If the enforcement process takes too long to initialise dependencies or inspect state, the additional delay can undermine the responsiveness of an AI coding workflow.

Igor describes sub-millisecond performance under cold-start conditions as a key challenge.

His approach includes keeping heavy dependencies out of the critical path, using in-memory data structures and compiled patterns, caching previously recorded lessons, and keeping the core evaluation path synchronous.

He also experimented with using a small local language model to classify proposed actions. In his experience, the additional latency and resource consumption did not justify using another model as the final decision-maker. He ultimately favoured deterministic, CPU-local verification.

This engineering decision reinforces the product's central philosophy: the component responsible for blocking dangerous actions should be fast, predictable, and independently testable.

Making Basic Developer Safety Accessible

Igor's approach also considers accessibility.

Developers can begin evaluating ThumbGate locally using:

npx thumbgate init

According to Igor, the free evaluation workflow includes local secret scanning, blocking selected destructive shell and Git operations, feedback capture, and single-agent pre-tool gating.

The Pro offering is intended for more advanced requirements, including multi-agent coordination and synchronisation of lessons across environments.

Developers can review the current features and pricing on the ThumbGate pricing page.

The underlying philosophy is that basic safeguards for an individual developer's machine should be accessible, while more advanced coordination capabilities can support a commercial product.

What Developers Should Establish Before Building an AI Agent

Igor's advice to developers building autonomous agents is direct: establish the safety boundary before building the agent's intelligence.

Before writing prompts or connecting an agent to tools, developers should determine which actions are forbidden, which require explicit approval, and what isolation is necessary to protect the surrounding environment.

These rules should be enforced at the appropriate system boundaries rather than left entirely to the model's discretion.

This becomes increasingly important as agents gain access to repositories, credentials, production systems, and long-running workflows.

The more autonomy an agent receives, the more important it becomes to define what it cannot do.

Looking Ahead: More Capable Agents Need Stronger Boundaries

As AI models become more capable, Igor expects the security challenge to extend beyond obviously destructive commands.

Agents may undertake multi-day tasks, coordinate other agents, retrieve external packages, and make changes across complex systems. Risks could include compromised dependencies, malicious instructions embedded in external content, and subtle modifications to sensitive configuration.

Future safeguards will need to evaluate more than command text alone. They may need to consider system state, dependency provenance, and deeper invariants that must remain true throughout a workflow.

For Igor, this is a continuation of the same reliability principles that shaped his earlier work in distributed systems: critical guarantees must be enforced by mechanisms capable of enforcing them.

The Takeaway: Treat AI Tool Calls as Untrusted Input

Igor's central message to developers is that AI safety should be approached as an engineering discipline, not simply as an exercise in writing better prompts.

AI models can be powerful reasoning engines without being reliable authorities over every action they propose. When their tools can modify files, change infrastructure, or access sensitive information, the surrounding system must enforce appropriate boundaries.

Secure software engineers do not execute arbitrary database input simply because it appears harmless. They validate it and apply controls before acting on it.

Igor believes AI tool calls deserve the same discipline.

The path towards more autonomous software engineering is not necessarily to trust agents more. It is to build systems where mistakes are constrained, actions are verifiable, and dangerous operations can be stopped before they cause damage.

That is the engineering challenge Igor Ganapolsky is addressing with ThumbGate—and an important principle for developers building the next generation of autonomous software.


About Igor Ganapolsky

Igor Ganapolsky is a Founder and Forward Deploy AI Engineer at ThumbGate, based in Florida, USA. His work focuses on AI-agent security, infrastructure enforcement, distributed-systems reliability, and developer tools.

Through ThumbGate, he is working on ways to evaluate AI-agent tool calls before execution, turn feedback into persistent safeguards, and make autonomous coding workflows more reliable.

Interviewed by Mehadi Hasan for CoderLegion Developer Stories.

1 Comment

1 vote
🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

I’m a Senior Dev and I’ve Forgotten How to Think Without a Prompt

Karol Modelski - Mar 19

Beyond the 98.6°F Myth: Defining Personal Baselines in Health Management

Huifer - Feb 2

The Senior Angular Take‑Home That Made Me Rethink Tech Interviews

Karol Modelski - Apr 2

Beyond the Crisis: Why Engineering Your Personal Health Baseline Matters

Huifer - Jan 24

The Zero-Net-Loss Fleet & The Mercenary Squad: A Live AI Economy

DEVPlank - Aug 4
chevron_left
16.4k Points • 458 Badges
Australia • coderlegion.com
108Posts
641Comments
469Connections
I’m a versatile software developer and tech generalist with a strong focus on building, analyzing, a... Show more

Commenters (This Week)

12 comments
3 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!