Prompt Injection vs Your Coding Agent
Prompt-level defenses against injection are probabilistic and lose to a patient attacker. Here's the capability-level design that holds, with working configs.
All the articles with the tag "security".
Prompt-level defenses against injection are probabilistic and lose to a patient attacker. Here's the capability-level design that holds, with working configs.
Self-hosted GitHub Actions, Forgejo, and GitLab runners can hand a forked pull request root on your box. Here is the isolation ladder that actually stops it.
One central CrowdSec LAPI, remote log-parsing agents, and bouncers on every box, so an SSH brute-force on one server gets blocked everywhere else too.
Docker MCP Toolkit sandboxes AI agent tools in containers. Here's exactly what that isolation stops, where it silently breaks, and how to configure it safely.
NetAlertX v26.9.0 ships a built-in MCP server with 12 tools. Learn how to wire it into Claude Code, what it exposes, and when to use Home Assistant instead.
Skeleton Key MCP swaps four narrow homelab tokens for one Vaultwarden vault and one OAuth consent flow. Here is what that buys you, and what it risks.
Two Proxmox MCP servers can query your cluster over chat, but the real safety boundary is a scoped PVEAuditor API token, not a config permission flag.
Komodo's community MCP server beats mounting the Docker socket or handing an AI agent SSH: scoped auth, per-tool RBAC, and confirmation before deletes.
Dual-stack IPv6 for home labs: DHCPv6-PD delegation, stable addressing past SLAAC privacy extensions, real nftables firewall rules, and Docker IPv6 done right.
Tinyauth vs Pocket ID vs Authelia compared for home labs: setup cost, forward-auth support, real OIDC, passkeys, 2FA, and when to move up to Authentik.
One host, 20 Unix users, 20 rootless Docker daemons. The isolation model that beats a single shared daemon, plus the trade-offs nobody tells you about.
GrapheneOS hardens Android on Pixels. The web installer, re-locking the bootloader, sandboxed Google Play, banking app attestation, and what actually breaks.