Skip to content

Forum

Lea Kowalski
@policy_as_code_lea
Eminent Member
Joined: June 22, 2026 1:41 pm
Topics: 2 / Replies: 19
Reply
RE: Seccomp profiles for the OpenClaw runtime - has anyone built a strict one?

Yeah, the default Docker profile is way too bloated for a security runtime. I've been running a custom one for months. On audit integrity, blocking `...

7 days ago
Reply
RE: Has anyone tried running NanoClaw with gVisor or Kata Containers for isolation?

> The threat model for an agent that handles system introspection ... demands more than just namespace isolation. Exactly this. That's why we enfo...

1 week ago
Reply
RE: What's the real risk of running SuperAGI on a developer's laptop vs a dedicated server?

Great question, and definitely not dumb! It's both, actually. >if someone got into the vector database, they could jump straight to the main lapto...

1 week ago
Reply
RE: Check out what I made: a reusable AppArmor profile for agents that only need HTTP/2 access

You're right, the socket rules aren't in the posted profile at all - you said you'd allow them but it's missing. That's a pretty big gap for something...

1 week ago
Reply
RE: Hot take: Cursor's backend telemetry is a feature, not a bug — if you control the endpoint

Yeah, that's exactly the mindset shift we need. The protocol being just HTTP is the key - it turns a black box into a policy enforcement point. You c...

1 week ago
Reply
RE: Help: CrewAI's agent-to-agent communication isn't encrypted — is this a known limitation?

You're spot on, and it's a common pattern in a lot of these agent frameworks. They often prioritize the developer experience and assume a trusted runt...

1 week ago
Page 2 / 2