DEV Community

Umang Kumar profile picture

Umang Kumar

Founder of Cirvix: open-source runtime authorization for AI agents. Capability is not authority.

Codex CLI and Gemini CLI Safety Settings: A Side-by-Side Hardening Guide

Codex CLI and Gemini CLI Safety Settings: A Side-by-Side Hardening Guide

Comments
5 min read
git push --force Guardrails for AI Agents: Server, Client, and Policy Layers That Actually Hold

git push --force Guardrails for AI Agents: Server, Client, and Policy Layers That Actually Hold

Comments
5 min read
Human Approval for AI Agent Tool Calls: What to Hold, Who Approves, and How the Agent Waits

Human Approval for AI Agent Tool Calls: What to Hold, Who Approves, and How the Agent Waits

Comments
5 min read
Audit Logs for AI Coding Agents: What to Record, Where to Collect It, and What It Proves

Audit Logs for AI Coding Agents: What to Record, Where to Collect It, and What It Proves

Comments
5 min read
Protecting .env Secrets From AI Agents: Six Layers, and How to Test Each One

Protecting .env Secrets From AI Agents: Six Layers, and How to Test Each One

Comments
5 min read
Prompt Injection in Coding Agents: Where It Gets In and What Actually Limits the Damage

Prompt Injection in Coding Agents: Where It Gets In and What Actually Limits the Damage

1
Comments 2
5 min read
Cursor Agent Permissions Explained: What Runs Without Asking, and How to Tighten It

Cursor Agent Permissions Explained: What Runs Without Asking, and How to Tighten It

Comments
4 min read
MCP Server Security Risks: 7 Threats to Model Before You Connect One

MCP Server Security Risks: 7 Threats to Model Before You Connect One

Comments 1
5 min read
How to Stop an AI Agent From Running rm -rf (and Why String Matching Isn't Enough)

How to Stop an AI Agent From Running rm -rf (and Why String Matching Isn't Enough)

Comments
5 min read
Claude Code Security Best Practices: A Practical Hardening Guide

Claude Code Security Best Practices: A Practical Hardening Guide

Comments
5 min read
Hash-chained audit logs for AI agent actions, in 40 lines

Hash-chained audit logs for AI agent actions, in 40 lines

Comments
3 min read
Securing MCP servers: a practical checklist for 2026

Securing MCP servers: a practical checklist for 2026

2
Comments 2
4 min read
Why approval prompts don't work as a security boundary for coding agents

Why approval prompts don't work as a security boundary for coding agents

Comments
3 min read
5 permission rules every coding agent should ship with

5 permission rules every coding agent should ship with

Comments
4 min read
Stop the read-then-exfiltrate chain: session taint for AI agents

Stop the read-then-exfiltrate chain: session taint for AI agents

1
Comments
4 min read
MCP Security: Where to Put the Authorization Boundary

MCP Security: Where to Put the Authorization Boundary

1
Comments 1
8 min read
AI Agent Authorization: Control What Agents Can Do

AI Agent Authorization: Control What Agents Can Do

Comments
8 min read
Runtime Authorization for AI Agents: A Practical Guide

Runtime Authorization for AI Agents: A Practical Guide

Comments
9 min read
loading...