HNHacker News
TopNewBestAskShowJobs

devendra116

8 karma · joined December 6, 2022

devendra116.com
submissionscomments
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
if a agent has the keys in the same process, it can easily extract them
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
interesting, how do you use mitmproxy for calling openAI llm ? or what exactly you use it for ?
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
which agent framework or tool gives guarantee for leaks?
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
does you agent only print "Hello World" on console ? or it uses any service ;)
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
if you usecase is just about dealing with private key and txn signing why not use any KMS service?
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
so you prefer using separate VM machines?
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
something that you dont like about using AWS secrets Manager or think it should be handle differently?

im researching around building a execution environment that handle the secret + actual execution, any input is appreciated

devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
so do we need something like `safe agent execution layer - that is policy enforced` (SEAL) we can manage what should be allowed and what not

agent uses llm to plan the action, but the actual execution happens in SEAL.

any example where it would make sense to start with?

open for thoughts

devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
is there any tool that can do this ?
devendra116··on Ask HN: Do you trust AI agents with API keys / private keys?
keyring is one of solution but even substituting values at excution does not gaurantee the security as agents can read the process itself.

im building a safe agent execution layer, A runtime where agents can act, but cannot access secrets. kinda sidecar that is callable by agent for using api keys, secrets, private keys, etc and plus one can add policy on how and what a agent can do.

does this seems good?

devendra116··on Show HN: A playground to test stablecoin gas fees and concurrent txns on Tempo
For those interested, the playground uses a guest wallet stored on browser localstorage so there’s no signup friction.