klotz: egress control*

0 bookmark(s) - Sort by: Date ↓ / Title / - Bookmarks from other users for this tag

  1. Taylor Luttrell-Williams writes that LLM coding agents create a new secrets-leakage pathway: they read local files (env files, credential profiles, SSH configs) as context and forward that content to external model providers before any traditional security gate—commit, pull request, or CI—can catch it. The article argues organizations should treat agent context as an egress surface and apply deterministic, model-independent secrets detection at the moment an agent decides what to read and transmit.
    - The 2025 Verizon DBIR reports a 94-day median to remediate leaked secrets found in GitHub repos, but agent workflows make that window moot because the secret has already left the local environment.
    - Supply-chain campaigns like Mini Shai-Hulud specifically target coding-tool configuration files, making agent context an active attack surface.
    - Sonar's agent plugins for Claude Code, Copilot, Codex, and Cursor block credential-shaped values in prompts and file reads before they reach a model provider.

Top of the page

First / Previous / Next / Last / Page 1 of 0 SemanticScuttle - klotz.me: Tags: egress control

About - Propulsed by SemanticScuttle