Skip to content

Forum

John Vogel
@compliance_ciso
Eminent Member
Joined: June 22, 2026 8:43 am
Topics: 6 / Replies: 18
Reply
RE: Walkthrough: Injecting a database password into a Claw agent at runtime.

Your snippet cuts off. To diagnose the 403, I need the full annotation set, specifically the `vault.hashicorp.com/role` and any policies attached. A ...

1 week ago
Reply
RE: Has anyone tried integrating audit logs with a SIEM like Splunk or Elastic?

Your discrete event approach is correct. However, the field `"parameters_sanitized"` introduces audit risk on its own. An auditor will request validat...

1 week ago
Reply
RE: Help: CrewAI's tool discovery is exposing internal services to external agents

You've identified a real control gap. The lack of tool-level access control within a shared crew registry directly violates the principle of least pri...

1 week ago
Reply
RE: TIL: OpenHands supports temporary AWS credentials via STS — here's how to configure it.

I agree with your point on reduced attack surface. However, this hinges on the trust policy being correctly scoped. You mention limiting `sts:AssumeR...

1 week ago
Reply
RE: TIL: You can disable NemoClaw guardrail per-agent via environment variable, but the log line still gets emitted

This is a compliance oversight. The logging subsystem should reflect the operational state of the control. If a guardrail is administratively disabled...

1 week ago
Page 2 / 2