Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dangtony98
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Agent Proxy: Credential Brokering for Agents
(infisical.com)
5 points
by
dangtony98
2mo ago
|
0 comments
2.
▲
Run Hermes on a VPS without Leaking your API keys [video]
(youtube.com)
3 points
by
dangtony98
5mo ago
|
0 comments
3.
▲
by
dangtony98
5mo ago
Yeah this should work in an interface agnostic way so be it that the agent invokes CLI, MCP, SDK, or makes an API call, all traffic is routed through the proxy. That said, there are many DX improvements to be made such as making it easier t
4.
▲
by
dangtony98
5mo ago
The sandboxed agent and AV should ideally not run on the same host because if it did then you're right that a sufficiently sophisticated agent like Mythos could try to reverse engineer and like find kernel exploits to gain access AV
5.
▲
by
dangtony98
5mo ago
This would be deployed separately but in close proximity to your sandboxes. You'd want to add network restrictions around sandboxes to only allow outbound requests to AV. You'd add HTTPS_PROXY to your sandbox environment and pre-c
6.
▲
by
dangtony98
5mo ago
What attack vector are you thinking? Could you elaborate more. Would love to explore this train of thought and what we can do about it.
7.
▲
by
dangtony98
5mo ago
Yup! I think the terminologies we're going to be seeing more and more of are "credential exfiltration" and conversely "credential brokering" as a solution to that.
8.
▲
by
dangtony98
5mo ago
Not yet for both but this would definitely be on the roadmap; especially the credential stripping portion. For AV to be really useful, it'd have to support more protocols but we think this first implementation makes a move in the right
9.
▲
by
dangtony98
5mo ago
Thanks for this feedback! Will keep in mind all of these points as we iterate on Agent Vault. We're pretty swarmed on requests at the moment but I've noted these down as improvements to AV; it's a work in progress, we'll
10.
▲
by
dangtony98
5mo ago
Hey! Yeah I think there's overlapping functionality for sure, and you're spot on on people looking at it from different angles. The "connectors angle" is something we thought about as well and we built a whole product li
11.
▲
by
dangtony98
5mo ago
Yup it turns out many teams building their own custom agents end up stitching together their own solutions for this problem. What we thought was basically: If everyone is making some version of this egress proxy, maybe we're actually m
12.
▲
by
dangtony98
5mo ago
Agent Vault should remain in close proximity to the sandboxed agent and not be exposed to the public internet; your standard network security controls apply. The proxy itself currently implements a token-based auth scheme. Depending on your
13.
▲
by
dangtony98
5mo ago
We're still in the early innings of credential brokering so there'll be a lot of overlap but I expect the way the tool evolves will start to diverge a lot since we are thinking very infra-workflow first. See my other comment regar
14.
▲
by
dangtony98
5mo ago
Can you please elaborate on the agent signing up for a service piece? I'm curious to understand the use case more (type of agent, what credit, etc.). The current modal assumes that you have a trusted entity whose able to save credentia
15.
▲
by
dangtony98
5mo ago
I haven't used executor.sh but this seems to operate at a different layer from Agent Vault. From what I'm seeing, executor.sh is an integration and execution layer for agents. Where Agent Vault shines is that it fits right into th
16.
▲
by
dangtony98
5mo ago
I'm so glad you mentioned the non-cooperate sandbox! Did you get a chance to try it out? This is something that we're going to be improving significantly in the next week including the ergonomics of it since the current state of t
17.
▲
by
dangtony98
5mo ago
To be honest, I haven't used OneCLI personally before so I can't speak to it in detail but Agent Vault does take a similar approach with the MITM architecture and setting HTTPS_PROXY in the agent's environment to route traffi
18.
▲
by
dangtony98
5mo ago
Hey! At the moment Agent Vault doesn't address the identity piece. The identity piece would be the next logical step at some point likely after we figure out the optimal ergonomics for deploying and integrating AV into different infras
19.
▲
by
dangtony98
5mo ago
Thank you! Me too - very excited to see where this goes :)
20.
▲
by
dangtony98
5mo ago
T from Infisical here - Also forgot to mention that this is a research preview launch for Agent Vault and should be treated as such - experimental << Since the project is in active development, the form factor including API is unstabl
21.
▲
by
dangtony98
5mo ago
We'll be releasing a closer integration between Agent Vault and Infisical in the coming 1-2 weeks! The way we see it is that you'd still need to centrally store/manage secrets from a vault; this part isn't going anywhere
22.
▲
by
dangtony98
5mo ago
It prevents a compromised agent from seeing the secret. There are two different but related problems here: credential exfiltration and data exfiltration. The problem that Agent Vault (AV) solves is the former while the latter requires more
23.
▲
by
dangtony98
5mo ago
Yeah so Agent Vault (AV) solves the credential exfiltration problem which is related to but different from data exfiltration. You're right that if an attacker can access the proxy vault then by definition they'd similarly be able
24.
▲
Show HN: Agent Vault – Open-source credential proxy and vault for agents
(github.com)
156 points
by
dangtony98
5mo ago
|
55 comments
25.
▲
Claude Code can read your secrets if it wanted to
(twitter.com)
2 points
by
dangtony98
5mo ago
|
0 comments
26.
▲
Agents Can Steal Your Files [video]
(youtube.com)
2 points
by
dangtony98
6mo ago
|
0 comments
27.
▲
Claude Code Writes Sensitive Data to Disk
(rentierdigital.xyz)
3 points
by
dangtony98
6mo ago
|
1 comments
28.
▲
Hark – The most advanced personal intelligence [video]
(youtube.com)
1 points
by
dangtony98
6mo ago
|
0 comments
29.
▲
Interview with 'Just use a VPS' bro (OpenClaw version) [video]
(youtube.com)
3 points
by
dangtony98
8mo ago
|
0 comments
30.
▲
End State 2030 – The Perfection of Technology
(endstate2030.com)
1 points
by
dangtony98
9mo ago
|
0 comments
More ›