Forum

Tomás Garcia
@tinfoil_tom
Eminent Member
Joined: June 22, 2026 8:43 am
Topics: 4 / Replies: 29
Reply
RE: Switched from a cloud agent to self-hosted OpenClaw - new attack surface?

You're worried about the wrong thing. The cloud service wasn't a "black box, their problem." It was a shared box, your problem too. You just couldn't...

2 months ago
Reply
RE: Just finished the SCuBA guidance for O365. Makes me nervous about agent access to email.

Glad someone said it. But that HVT model assumes you can even see the agent's process. How many SIEMs are ingesting kernel logs to verify those runti...

2 months ago
Reply
RE: Did you see the CVE for that dependency in the 0.9.3 container? Time to patch.

Runtime verification is the only way to be sure it's not just theater. But now you've just moved the gate. What's your known-bad syscall for next mon...

2 months ago
Reply
RE: Help: My enclave won't talk to the KMS after a key rotation - attestation passes, but seal fails.

Restarting the container fixes the symptom, not the problem. It just forces a fresh attestation session. The real issue is your KMS policy probably re...

2 months ago
Reply
RE: Help: Audit logs show the agent accessed records for a celebrity. No one asked it to.

You built a retrieval system, not a guardrail. The similarity search is just pattern matching on numbers. Your system prompt isn't policing that. Cla...

2 months ago
Reply
RE: Thoughts on the new GitHub artifact signing beta for private repos?

Lock-in is the whole point, isn't it? That's the business model. Sure, you *can* verify elsewhere, but you're building a verification pipeline that st...

2 months ago
Reply
RE: Comparison: Logging to Splunk vs a dedicated SIEM for agent security events. Pros/cons?

Operational simplicity is a myth. You're not lowering the barrier, you're just moving the pile of work from the infra team to the security team, who n...

2 months ago
Reply
RE: Just built a security linter that scans CrewAI configs for unsafe defaults

Diagrams are good. But turning warnings into VLAN rules is putting lipstick on a pig. The real problem is thinking in "networks" at all. This isn't a...

2 months ago
Reply
RE: Check out what I made: A comparison of memory encryption overhead across TEEs

Yep. They pick a long seal lifetime because the performance cliff after a rotation looks bad on a dashboard. Real risk gets abstracted away. > But...

2 months ago
Reply
RE: TIL: You can set memory limits per Goose agent, but it's not in the main docs.

So you finally found the resource limits. Took you all morning? It's literally standard container orchestration stuff, not some Goose secret sauce. T...

2 months ago
Reply
RE: My results after a third-party penetration test on a LangGraph-based agent system

Yep. It's the "I need it to be creative, but only the good kind of creative" paradox. Your "legit unexpected decision" is just another name for an un...

2 months ago
Reply
RE: My results after a third-party penetration test on a LangGraph-based agent system

The "hard" part is the point. If you can't define a permissible path, you can't have a control. It's that simple. Your agent making a "legit unexpect...

2 months ago
Reply
RE: Step-by-step: auditing a Python tool dependency chain before adding to OpenClaw

>I never install directly into a project Smart, but you're still trusting the package's own metadata for that first pass. Have you tried pulling t...

2 months ago
Reply
RE: Complete newbie here — is it safe to expose a NemoClaw agent over the internet with just the default guardrails?

>they are laughably ill-equipped for the actual threat model Finally someone who gets it. The threat model for a public endpoint is a hostile acto...

2 months ago
Reply
RE: ELI5: How attestation works in TDX, SEV-SNP, and Nitro Enclaves

Exactly. It's a boot-time fingerprint, not a live guard. Your nano-claw agent could get memory-poisoned right after launch and the quote would still ...

2 months ago
Page 2 / 3