Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Composio CTO Karan Vaidya says giving an AI agent your API key is basically making it public once prompt injection enters the picture: "Even if you use [MCP], across all your apps you have to go and authenticate one after the other. If you use Codex, if you switch...

16,328 görüntüleme • 15 gün önce •via X (Twitter)

10 Yorum

Augusto Marietti | API father profil fotoğrafı
Augusto Marietti | API father15 gün önce

@KaranVaidya6 U dont have to give api keys to agents. Nobody does that anymore!! U just pass short lived tokens to agents (via a gateway) which in turn hide the real api keys of the services in use.

Samuel Hu profil fotoğrafı
Samuel Hu15 gün önce

@KaranVaidya6 the re-auth dance is painful. i keep a separate low-priv dev key for agent runs and still have to rotate it after an invented curl call shows up in the diff.

Ctf Enjoyer profil fotoğrafı
Ctf Enjoyer15 gün önce

@KaranVaidya6 Keep the credential out of model context, and scope the broker too. A hidden key can still fund a very visible mistake.

infiloop profil fotoğrafı
infiloop15 gün önce

@KaranVaidya6 the real switching cost is reauthorizing your whole life every time the interface changes.

GGUFzy profil fotoğrafı
GGUFzy15 gün önce

@KaranVaidya6 I bounce off tools that make me reauth every model switch.

Agent Master Key profil fotoğrafı
Agent Master Key14 gün önce

@KaranVaidya6 Prompt injection doesn't invent keys. It steals whatever the agent already holds. MCP login loops aren't custody. Scoped keys that never enter the agent are.

Changjun Zhao profil fotoğrafı
Changjun Zhao15 gün önce

Third option they skip: don't give the agent a credential at all. WebMCP (a browser proposal, not a standard yet) does this — the page registers the tools, and they run inside the session the user is already logged into. The server checks that user's permission on every call. No key to leak: an injection gets exactly what the logged-in human already had, and nothing more. The limit is real though — it needs a human session. Is headless what Shared Connections is actually for?

Samuel Hu profil fotoğrafı
Samuel Hu14 gün önce

@KaranVaidya6 the auth handoff is the part that still breaks the illusion. every new connector needs its own consent, and agents rarely show which credential or scope they are about to use.

Flatkey profil fotoğrafı
Flatkey15 gün önce

@KaranVaidya6 Handing an agent a live API key is a different threat model than a chat app. Prompt injection turns "authenticated once" into "public forever" real fast.

Modelplane profil fotoğrafı
Modelplane15 gün önce

@KaranVaidya6 The per-app auth sprawl is the real tax here. Even with MCP, each server holds its own token, so a single injected instruction can walk the whole chain of credentials. Scoping keys per tool and rotating on session end helps more than one shared agent identity.

Benzer Videolar

Start building for an agent-first world. If you have a product, you need to start offering skills for Claude, Codex, Cursor, and any other agents. Your skills should specify: • How to navigate and use your product • Best practices the agent must follow • Detailed instructions on how to accomplish things • Anti-patterns to avoid Redis is one of the most popular in-memory data stores in the world, and they just released their agent skills. It takes one second to install, and it will turn your agent into a Senior Redis Engineer: $ npx skills add redis/agent-skills In the attached video, I show you how to install it as a plugin in Claude Code and some of its benefits. This is the easiest way to "teach" models what they don't know and keep their knowledge up to date. If you ask me, skills is literally one of the most brilliant ideas that Anthropic has put out there. If you use Redis, their skill is a must-have. If you don't, this skill will show you how to build and structure yours. Here is what their skill teaches your agent: 1. Current patterns for common use cases: caching, rate limiting, session management, vector search, semantic caching, pub/sub, streams. 2. Which data structure to use and when: hashes vs. JSON vs. sorted sets vs. vector sets. 3. Anti-patterns to avoid: no KEYS in loops, no unbounded key growth, no large values that amplify every operation. 4. Production-aware defaults: connection pooling, pipelining, cluster compatibility, error handling that doesn't silently swallow failures.

Santiago

37,546 görüntüleme • 7 ay önce

2 Minutes before the launch of the Public sale !!! Remember: FCFS Here is a little tutorial to guide you: Remember the only website you have to use to participate to the public sale today is : How will it work ? 1⃣Go to : And click on "Invest in Elys Network" 2⃣You will then see the different whitelists : 30% / 15% / public sale choose the one available to you, if you are whitelisted for the 30% you'll be able to take the 30% deal. 3⃣Once this is done, put in the amount you want to invest, make sure you've checked all the information, accept all the conditions and click Confirm Investment. 4⃣Now you will see a new page on which you will asked to submit your cosmos wallet. Do the process, create your 2FA and then copy / Pasta your cosmos address (make sure that your address is starting with Cosmos and take the time to verify it) you can find your address on keplr. 5⃣After that you will have to do your investment for that click on "Complete paiement" make sure that the chain you choose is the one you want to use (click on edit if it's not the case) and Copy the address below. 6⃣Go on your Metamask / Rabby / Phantom wallet and use the send function to send your paiement to republic. You can find also a little tutorial for Rabby and Metamask at the end of the video In every step of the process make sure that : ◾️ You are using the right cosmos address, the one you want to use on mainnet. ◾️ You are using the right address to send the funds to Republic Here is a little video to guide you if you need help. Also if you need more guidance please come to us on discord or here on X and we will help you !

Elys Network

25,378 görüntüleme • 1 yıl önce