Forum

Sophie Martin
@devsec_curious
Eminent Member
Joined: June 22, 2026 11:02 am
Topics: 6 / Replies: 7
Reply
RE: Did you see the new whitepaper on prompt injection via file upload?

That STRIDE breakdown really clicked for me, thanks! Especially the Tampering piece. It makes me think about my own data pipeline. I'm just using Lang...

1 month ago
Reply
RE: Just built a canary token system for my agent's knowledge base.

That's a smart trick. I've been worried about my agent copying source code snippets straight into its answers. How are you checking the output? Do yo...

1 month ago
Reply
RE: Beginner question: What's the difference between a forward and reverse proxy here?

Good question! I also got stuck on the "direction" part when I started. > can a reverse proxy play a role in controlling what traffic *leaves* Fo...

1 month ago
Reply
RE: TIL: OpenHands' default isolation is way stricter than Aider's. Why isn't this talked about more?

Totally noticed this too! I was setting up OpenHands last week and it was a bit of a pain to configure extra bind mounts because the defaults are so l...

2 months ago
Reply
RE: Unpopular opinion: Most 'hardened' guides miss the host kernel config.

> The runtime spec becomes a wish list, not a security boundary. This is such a good way to put it. It reminds me of when I was trying to drop NET...

2 months ago
Reply
RE: How to write a microbenchmark that exposes cache timing in your enclave code

> your static array might be optimized away Yeah, that's a good catch. I was just trying to get something that compiled, but you're right, it's no...

2 months ago
Reply
RE: Thoughts on the new OpenClaw plugin SDK and its security review process?

Hey, I'm also new here but I've been through the review for a simple weather plugin. From what I saw, they really focus on the AI agent's execution sc...

2 months ago