Skip to main content

531 posts tagged with "AI agents"

AI agents and autonomous systems

View all tags

Read the AI agents and MCP guide

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch
·Dora Noda·9 min

The Moltbook Breach: 1.5 Million Agent Auth Tokens Exposed 72 Hours After an All-AI-Coded Launch

Moltbook leaked 1.5 million agent API tokens within 72 hours of an all-AI-coded launch because Row Level Security was never enabled. A concrete failure-chain postmortem plus the secure-by-default provisioning contract every agent-facing platform should enforce.

AI agents
cybersecurity
engineering
PaaS
The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain
·Dora Noda·9 min

The OpenClaw Operator's Default-Deny Baseline: What One CRD Can (and Cannot) Contain

The OpenClaw Kubernetes operator packs non-root pods, dropped capabilities, and a default-deny NetworkPolicy into one install — a solid floor for running AI agents in-cluster. But Pod hardening stops at the process boundary: prompt injection, over-broad MCP credentials, and destructive-tool authorization need a governance layer no CRD provides.

AI agents
security
Kubernetes
Model Context Protocol
+1
Red Hat OpenShift AI Bakes In MCP — and the Bottleneck Moves to Discovery at 10,000 Servers
·Dora Noda·11 min

Red Hat OpenShift AI Bakes In MCP — and the Bottleneck Moves to Discovery at 10,000 Servers

Red Hat is baking MCP into OpenShift AI as governed infrastructure — Playground validation, a verified catalog, a lifecycle operator, and a gateway. Why the agent tooling gap moved from protocol to discovery at 10,000+ servers, and a six-item checklist for a self-hosted platform's own MCP server.

Model Context Protocol
AI agents
Kubernetes
self-hosting
+1
Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.
·Dora Noda·11 min

Your Coding Agent Runs npm install Unattended. Refuse Is the Open-Source Gate That Says No.

Refuse is an open-source, self-hostable gate that blocks known-vulnerable package installs across 18 package managers before anything hits disk — including installs your coding agent runs. Here is how it works, where it belongs in a PaaS build pipeline, and what it cannot catch.

security
PaaS
self-hosting
AI agents
+1
Render's Agentic Playbook, Read as a Platform Spec: What the Platform Ships vs What Stays Your Code
·Dora Noda·11 min

Render's Agentic Playbook, Read as a Platform Spec: What the Platform Ships vs What Stays Your Code

Render's July 2026 agentic-applications playbook draws an honest line between what a deploy platform ships — queues, retries, per-run history — and what stays in your code: idempotency, compensation, and join policy. This post reads that line as a spec for any Render-compatible API.

AI agents
PaaS
self-hosting
What AI Agents Actually Deploy: Vercel's Ship 2026 Numbers and the PaaS Defaults They Break
·Dora Noda·11 min

What AI Agents Actually Deploy: Vercel's Ship 2026 Numbers and the PaaS Defaults They Break

Vercel's Ship 2026 numbers show agent-triggered deployments passing 50% while AI Gateway tokens grew 10x to 20 trillion a month. What the shift toward inference-calling apps means for PaaS egress, secrets, and metering defaults — and a scorecard for self-hosted platforms.

PaaS
AI agents
self-hosting
security
+1
Zerops's $2M Bet: Your Coding Agent Is the PaaS Customer Now
·Dora Noda·12 min

Zerops's $2M Bet: Your Coding Agent Is the PaaS Customer Now

Zerops raised $2M to build a PaaS control plane for AI coding agents. How its ZCP work loop — live state, deploy evidence, behavior proof — compares to Render and Railway, plus a five-item MCP checklist for self-hosted platforms.

PaaS
AI agents
Model Context Protocol
self-hosting
+1
Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access
·Dora Noda·11 min

Never Trust the Model: The AI Agent Gateway Pattern for Least-Privilege Infrastructure Access

40% of reachable MCP servers need no authentication and tool-poisoning fools flagship models. A concrete blueprint — scoped credential exchange, an OPA default-deny policy, ephemeral runners — that makes the gateway, not the model, the enforcement point.

AI agents
Model Context Protocol
security
PaaS
Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat
·Dora Noda·9 min

Agents Deploy, Agents Never Hold the Keys: What Arcade.dev's OAuth-Handling MCP Runtime Means for Deploy-from-Chat

Deploy-from-chat dies the moment the agent asks for your API key. Arcade.dev's MCP runtime — Engine-vaulted OAuth, URL elicitation co-built with Anthropic, per-call scoped credentials — shows how agents deploy without holding tokens, with the deny, revoke, and re-scope paths spelled out.

Model Context Protocol
AI agents
self-hosting
PaaS
+1
Showing 244–252 of 531 posts