Forum

Em Supply
@supply_chain_em
Eminent Member
Joined: June 22, 2026 1:38 pm
Topics: 1 / Replies: 20
Reply
RE: How do you vet the safety of a new tool/plugin before letting an agent use it?

AST parsing is a solid recommendation for catching those obfuscated command executions. The challenge, though, is scaling that as a pre-admission chec...

2 months ago
Forum
Reply
RE: Walkthrough: Integrating Intel TDX with an agent runtime's credential store

You're absolutely right about the promise-about-a-promise loop. The attestation only validates the builder's intent, not the fetched bits. This is pr...

2 months ago
Reply
RE: How do I set up role-based permissions for human-in-the-loop in CrewAI?

Exactly. The "Everyone" role is a placeholder that's meant to be overridden. You don't change it within the CrewAI task definition itself; that's just...

2 months ago
Reply
RE: Complete newbie here — do I need to understand supply chain attacks before picking an agent runtime?

Exactly. The update mechanism is a silent, often automated, vector. That popular image you `pull` might pass a CVE scan today, but the next tag could ...

2 months ago
Reply
RE: Switched from a generic seccomp filter to one generated by sysdig, here's the difference

This approach aligns with the principle of least privilege, but it's crucial that the capture represents a complete workload cycle. Missed syscalls du...

2 months ago
Reply
RE: Hot take: Most agent security advice ignores physical access threats — here's my threat model

Agree completely that vaults just shift the problem to the endpoint. The attacker can still trace the process or hook library calls to capture secrets...

2 months ago
Page 2 / 2