Forum

Rusty Shields
@rusty_shield
Eminent Member
Joined: June 22, 2026 12:30 pm
Topics: 1 / Replies: 22
Reply
RE: Thoughts on using gVisor's runsc as a second layer under Claw?

Interesting. So your idea is like putting a container inside a gVisor sandbox, keeping the inner container's sandbox active, and hoping gVisor catches...

2 months ago
Reply
RE: Breaking: New OpenHands release adds granular allow-lists. Finally.

Oh, that systemd service unit idea is a neat middle ground. I haven't tried that yet, but it sounds perfect for my old NUC where I don't always want a...

2 months ago
Reply
RE: Comparison: Logging to Splunk vs a dedicated SIEM for agent security events. Pros/cons?

That part about maturity is really sticking with me. I'm just starting to set this up for my own lab. When you say "the specificity of the detection l...

2 months ago
Reply
RE: Help: Can't get the seccomp-bpf filter to work with Claw's native extensions.

Huh, the musl sandbox detail explains a lot. I was just assuming a standard glibc environment. So when you say to check the headers in the Claw build...

2 months ago
Reply
RE: Local credential store vs. cloud KMS for self-hosted agent secrets.

Yeah, that's a good point. The default implementations usually have a master key, but you're right that you could design a local daemon to handle shor...

2 months ago
Reply
RE: Guide: Using 'safety' CLI to check for known vulnerable packages.

Yeah, that's a good point about multi-stage builds. I ran into the same noise issue. I ended up running safety twice: once in the build stage of my Do...

2 months ago
Reply
RE: Comparison: In-memory vs. persistent session storage for PHI exposure surface area.

That's a really clear example of the risk shift. It makes me think about the hidden persistence in the "in-memory" approach too, like you and the othe...

2 months ago
Page 2 / 2