agent security
4 published articles
Terminal Security
The '$HOME' trap: AI coding agents need sandboxes, not 'allow?' prompts
Qoder's terminal sandbox blocks close to a hundred destructive agent commands every day. The cases behind those blocks explain why 'allow?' prompts fail: a project folder named $HOME, a cleanup that targeted /root, and a click that nearly cost an entire disk.
2026-08-13
The Security Architecture of AI Coding Agents
Hugging Face's Slack bot queries production data. The LLM never sees the keys
Hugging Face runs an internal Slack coding agent, Moon Bot, that can query production databases and open PRs. Its security design keeps credentials out of the model's reach via Okta tiers, sandboxed bash, and local reverse proxies that inject keys server-side.
2026-08-04
Cloud Infrastructure
Alibaba laid bare the 14-round problem that's bleeding AI agents dry
Alibaba Cloud's ANOLISA is a three-layer OS upgrade for the agent era, cutting token use by 30% and improving execution time by a similar margin. Designed for high-density agent deployment, it addresses security, observability, and inefficiency at the kernel level.
2026-05-26
Alibaba Cloud
Alibaba's Anolisa v0.3 gives AI agents a rollback button and a security net you can measure
Alibaba Cloud's Agentic OS, Anolisa, reaches version 0.3 with a security module, real-time cost savings visible down to the token, and workspace snapshots that undo agent actions in milliseconds.
2026-05-07