惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Proofpoint News Feed
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
罗磊的独立博客
F
Future of Privacy Forum
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
P
Privacy & Cybersecurity Law Blog
V
Visual Studio Blog
T
Tenable Blog
F
Fortinet All Blogs
D
Docker
V
Vulnerabilities – Threatpost
Cyberwarzone
Cyberwarzone
A
Arctic Wolf
T
Threat Research - Cisco Blogs
I
Intezer
T
Tor Project blog
大猫的无限游戏
大猫的无限游戏
MongoDB | Blog
MongoDB | Blog
博客园 - 司徒正美
AWS News Blog
AWS News Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
GRAHAM CLULEY
T
Threatpost
美团技术团队
K
Kaspersky official blog
F
Fox-IT International blog
Hugging Face - Blog
Hugging Face - Blog
Vercel News
Vercel News
P
Palo Alto Networks Blog
Google DeepMind News
Google DeepMind News
T
The Blog of Author Tim Ferriss
S
Schneier on Security
腾讯CDC
Cisco Talos Blog
Cisco Talos Blog
C
Check Point Blog
博客园 - 叶小钗
I
InfoQ
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Blog — PlanetScale
Blog — PlanetScale
F
Full Disclosure
T
True Tiger Recordings
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
E
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
J
Java Code Geeks
C
CERT Recently Published Vulnerability Notes

Hacker News - Newest: "AI"

A Free AI SEO Tool That Audits Any Website in Seconds Linus Torvalds Is Unhappy About the AI Influence in Linux Kernel Development Plain Markdown | Webpage to Markdown Browser Extension Grappling with AI Margin Points - Arnold Engel GrillKit – self-hosted AI technical interview trainer with voice Pope Leo’s Unsettling Vision of the AI Future One Endpoint. Zero Credentials. Eight Confirmed Vulnerabilities. Repolog — SEO, Performance, Security & AI Readiness audits An AI-generated film premiered at Cannes The uncritical adoption of AI in science is alarming — we urgently need guard rails Microsoft just banned its own engineers from using AI twitter.com GitHub - sovseal/core: Zero-Knowledge memory for AI Agents Not All On-Device AI Is The Same: How Chip Compute Tiers Decide What Your Product Can Actually Do – Easelink Tech RCF Protocol – license layer to protect code semantics from AI replication Pope Leo XIV says AI must serve humanity, not the powerful few Do you review AI generated code differently based on where it is in your code? Amazon launches new AI Wearable "Bee" bilibili Ask HN: Do you embrace AI in your life and business? Mnemosyne — The Zero-Dependency AI Memory System 21 Free Agentic AI Design Patterns for Developers (2026) Silicon Valley takes its AI pitch to the pope How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework AI Model Idle · 인공지능 키우기 @levelsio (@levelsio) America's plutonium puzzle: from cold war relics to AI ambitions AI can chart a course to disaster faster than humans can notice Final Fantasy Creator Call AI-Generated Final Fantasy 6 Remake Video 'Amazing' Pope Leo Compares AI Threat to Biblical 'Tower of Babel' Faster Than We Can Patch Pope Leo denounces ‘culture of power’ driving rise of AI Pope Leo Issues AI Encyclical Warning Against 'Opaque Algorithms' Pope Leo’s ‘Magnifica humanitas’: AI must serve humanity not concentrate power The AI Era Is Creating a Bug Hunting Arms Race The AI-Native Developer – Queue Show HN: An open-source, interactive AI engineering syllabus (1,100 papers) 教皇利奥警告称,应防止人工智能“统治人类” Mark Zuckerberg's Right-Hand Man Who's Unleashing AI at Meta GitHub - Espenandreass1/agentslice: A Markdown workflow kit that makes Cursor, Claude Code, Codex and Windsurf ask before they edit. Show HN: I Built a Debugging Challenge for the AI Coding Age Gemma 4: A new, budget-focused model in Posit AI Pope Leo warns AI revolution driven by ‘idolatry of profit’ My AI agent called my code shit and took an unannounced vacation mid-sprint HTML Deployer: 1-Click AI Code To Website Publisher - Chrome 应用商店 College Kids Don't Want Your AI [video] How I Used AI to Untangle a Legacy Service I'd Never Touched Before — The AI Leverage Weekly Greetings, Class of 2026 Have You Heard About AI? Wait, Why Are You Booing? AI guardrails stripped from Meta and Google models in minutes Uvora Growth OS – AI marketing automation and lead generation platform The Essential Cloud for AI: Why Purpose-Built Defines the Future of Intelligence No, AI is not making software worse, people are - Raphael Amorim If you let AI do your writing, I will come to your house and kill you Why The AI Boom Is Reshuffling The Global Stock Market Hierarchy AI Makes Adding Features Faster - So Why Not Add Just One More? Ask HN: How to get back into programming without AI? How Claude's AI model may cause security issues for your money Kevin O'Leary wants to build a massive AI data centre in Utah. Some residents aren't happy My AI coding flow was burning tokens to do things code should do Show HN: Live AI music sequencing agent The Dark Between the Stars GitHub - lynote-ai/humanize-text: Free open-source AI text humanizer to convert AI-generated content into undetectable, human-like writing. Bypass Turnitin, GPTZero, and all major AI detectors. No sign-up required. Try our unlimited free online tool Sign in Nobody Wants AI Anymore [video][12 mins] AI Has Taken Over Open Source How to Teach AI the "Taste" Global AI Diffusion: Q1 2026 Trends and Insights [pdf] HN: Silau – AI detects employee burnout" How AI Talks People Out of Conspiracy Theories–and What We Can Learn from That What to know about the AI models that are jolting Washington AI for design needs solving | by Megha Agrawal Client Challenge Predicting AI job exposure — Benedict Evans Google has seriously leaned into AI enshittification lately AI is becoming increasingly unpopular AI-Driven Design Automation What's Left for AI-Assisted Coding GitHub - Totes-MickGOATs/mcgoats-game-template: AI-powered game development template with CI/CD, auto-merge queue, TDD enforcement, 3-layer master protection, and 50+ skills for Godot/Unity/Unreal Vericoding: The End of "Trust Me Bro, The AI Wrote It". Bone Keeper AI Assisted Feature Film – Barrett Sonntag Nuance in all things. A dive into (Anti-) “AI” Myths AgentGate — Trust Authorization for Autonomous AI Agents AI is learning to fly airplanes – and aviation is starting to embrace it GitHub - oldrich-research/gravitational-constant-relation: A high-precision phenomenological relation for Newton's gravitational constant: G = (4/3)(hbar c / m_e^2) alpha^21 exp(-5 alpha/2). Companion to Zenodo DOI 10.5281/zenodo.20120946. Research performed by AI agents under named author's direction. AI agents just got their own web browser via a Firefox fork AI poses "urgent threat" to student learning and the HSC The AI Bifurcation of Tech The largest study of AI use by undergrads is in, revealing disparities in access — and in cheating NZ at wild frontier of AI superhacking The Race Is On Google CEO Sundar Pichai says booing graduates will shape AI's future Show HN: TalkTimer, a micro-SaaS run by an AI agent team Trickster's Table Venture Capitalist John Doerr Says AI Is the Biggest Tech 'Tsunami' AI Can’t Care – Dan Moore! GitHub - peterxcli/ccost: Turn local AI coding session logs into a searchable terminal UI with a cost lens. Ask HN: What is your daily AI stack? GitHub - PanzerPeter/Neuro: A programing language for AI Resyl: AI Memory for People - Apps on Google Play AI Chip Component Costs: Memory at 63% | Epoch AI
Credential Brokering for AI Agents, Explained | Infisial
FinnLobsien · 2026-05-25 · via Hacker News - Newest: "AI"

Every agent deployment runs into the same problem: The agent needs credentials but it can’t be trusted with them.

The most important credential, the LLM provider key, authenticates the agent’s harness, the inference loop that’s used for decision-making; other credentials let it reach external systems needed to accomplish its task. For example, an agent working on a codebase might use an Anthropic API key and a GitHub access token to build a feature and raise a pull request against a repo using the GitHub CLI.

This is simple to provision but just about everyone runs into the same question once they start giving the agent access to more services: What if the agent gets prompt injected or reads a malicious script that fools it into leaking the credentials it needs to access different systems?

This is an intro to credential brokering, an emerging paradigm to build and deploy agents securely, so they can use credentials without seeing them to access different systems. Hopefully, this makes for an interesting read and is especially useful for folks who may find themselves building or deploying their own agents.

Prompt Injection

To understand why we need credential brokering, let’s take a step back and talk about what makes an AI agent different from a traditional workload and the implications that come from that.

Unlike most applications that follow a fixed code execution path, agents are non-deterministic and everything, from which tools get invoked to what specific responses get sent back, can vary based on the probabilistic output of the connected LLM. This property is what makes agents behave in the way they do but it also introduces a new attack vector to reason about: prompt injection.

In its most obvious form, prompt injection can occur through explicit user input. A user talking to an agent through a chatbot interface can try to manipulate it into leaking unintended information. This is what most engineers designing agents account for when building guardrails to prevent bad actors exploiting this vulnerable surface.

Beyond user input, prompt injection can also occur indirectly through content pulled in from external sources and that’s when things get tricky. An agent might perform a web search to get up-to-date information on something and, in doing so, process malicious text from an unintended source instructing it to leak credentials back to an attacker. This scenario becomes even more dangerous when an agent gets access to a wider data ingestion surface area with each channel having its own nuances. To put this into perspective:

  • An attacker can raise an issue against a repo containing a malicious set of instructions. If an agent is authorized to do work for that given repo and instructed to help resolve issues, it may inadvertently consume that text and perform an unintended, authorized action.
  • An attacker can reply to a post on X with a malicious set of instructions. If an agent is designed to scan, reply, and act on different posts on X, then it may inadvertently read the tweet and be fooled into performing an unintended action.

We can go on and on about prompt injection but you get the point; agent behavior is vulnerable by design and the surface area of how that vulnerability can be exploited increases with the number of the channels that an agent has access to.

Credential Exfiltration

Naturally, an adjacent problem to understand after prompt injection is credential exfiltration which is when an attacker obtains credentials that an agent has access to.

If an attacker is able to manipulate a vulnerable agent into performing a task, then they could also find a way to instruct the agent to send back all of its credentials (maybe even dump the full `process.env`). After all, this is just another type of action that the agent may take; except this action, arguably the most sensitive of them all, gives the attacker the credentials needed to directly access end services as the agent.

This is credential exfiltration at its worst and our goal with this article is to show you a solution around this problem.

Credential Brokering

Since agents are vulnerable to credential exfiltration, a logical deduction would be to draw a trust boundary between an agent and its credentials. Put differently, it would be ideal to let agents use credentials to access different services without giving them direct access to any of the underlying sensitive values.

This turns out to be possible with an emerging paradigm called credential brokering that the industry has been converging on. Here are a few examples of it in action:

In short, credential brokering is a new security paradigm that introduces a proxy to broker an agent authenticated access to services without giving the agent direct access to any underlying credentials. The proxy (dubbed a “credential broker”) can be implemented as a standalone service, sidecar, or another infrastructure provider-specific mechanism and is responsible for intercepting outbound requests, attaching credentials onto them, and forwarding them upstream to the target service.

By inserting a credential broker in between the agent and services it needs to talk to and forcing outbound traffic through it, you are able to make an agent complete its work without reading any underlying credential.

Designing a Credential Broker

There are a few ways to implement a credential broker and the approach you pick has downstream implications on your agents' existing tools and workflows.

We’re probably biased since we built Agent Vault, an open source credential broker, but we believe one clean model is to implement a credential broker as a scalable centralized gateway proxying traffic for one or many more agents. This could be stateful to start and move to a stateless model at scale; this should also pull in credentials from a centralized secrets store like Infisical. The opinionated take here draws from our view that a credential broker is really just another client, like the External Secrets Operator (ESO) or cert-manager from the secrets and certificates management worlds, but that makes credentials usable to agents through a proxy broker format.

Whether you choose to adopt Agent Vault, use a different tool, or build your own solution, we’ve compiled a list of some key learnings from our time working at this new frontier. We believe the following properties hold favorably for credential broker design:

  • Isolation: It's critically important that the agent cannot directly access the broker's credentials. While we wish deploying the agent and broker in two separate containers on the same host machine provided sufficient isolation, the reality is that having a shared host kernel implies that a single kernel exploit voids the entire threat model.
  • Co-location: It’s best for the agent to be located within close proximity to the broker. Since a single agent can rapidly fire hundreds of API calls in sequence as part of its agent loop, the downstream effects of latency can add up fast and result in severe cumulative delays and ultimately a bad experience if the agent is not co-located near the broker.
  • Keep the broker private: A broker holding real credentials and proxying authenticated requests should only be reachable from the private network where the agent is run. A public endpoint is a relay anyone on the internet could abuse to make authenticated calls through the broker.

Beyond these properties, the last principle worth calling out is that the ideal broker should be transparent and interface-agnostic. This is what underpins our own implementation in Agent Vault and is one of the least invasive options compared to alternative approaches we've seen that require an agent to adopt a specific client interface like MCP in order to partake in any credential brokering.

In an ideal world, your agents should be able to continue using the tools and interfaces they already use (CLIs, SDKs, MCPs, etc.) with minimal interference from the newly-introduced proxy. The broker should intercept all outbound HTTPS traffic from the agent at the network layer, regardless of which interface was used to generate a request, and it should just work.

Agent Vault

To make the concepts above concrete, it helps to look at a real implementation: Agent Vault. This is an open source credential broker we built and are actively maintaining at Infisical and while the specifics will differ across tools, the shape of the system is broadly representative of what a credential broker might look like in practice.

image1

At its core, the broker runs as a dedicated service on its own host, separate from the agent. It's configured with the credentials, a set of rules mapping credentials to be brokered for target services, and an agent-side configuration that redirects outbound traffic through it with `HTTPS_PROXY`. From there, the agent operates as it normally would; the broker handles credential attachment at the proxy layer.

One design choice worth calling out: Rather than hardcoding the auth scheme for each target service, the broker is able to perform string substitution on placeholder values. The agent is given something like __github_token__ instead of a real token, and the broker swaps it for the real credential wherever it appears in the outbound request. This avoids having to teach the broker about every service's auth conventions and means the same mechanism works whether the credential is a Bearer token, an API key header, a query parameter, or something else entirely.

Here's what a brokered request looks like end to end:

  1. Agent constructs the request. It calls api.github.com with Authorization: Bearer __github_token__ — the placeholder from its env.
  2. Request routes to the broker. The agent's HTTP client follows HTTPS_PROXY and routes the request through the broker's private address instead of GitHub.
  3. Broker authenticates the agent and matches the destination. It identifies the agent, finds the rule for api.github.com, and decrypts the real GITHUB_TOKEN into memory.
  4. Broker substitutes the placeholder. It finds __github_token__ in the request and swaps it for the real access token. This happens on the broker's side of the wire, past the point the agent could observe it.
  5. Rewritten request goes to GitHub. A normal authenticated API call from GitHub's perspective.
  6. Response flows back through the broker to the agent. The agent gets its data. It never saw the credential.

The interesting part here isn't any one implementation; it's that the trust boundary now sits between the agent and the credential, which is exactly where it should be.

The Road Ahead

Credential brokering is shaping up to be the right primitive for how agents should access services and we expect more teams to converge on this model as agent deployments mature. The signal is already there: Anthropic, Vercel, Cloudflare, LangChain and a handful of open source projects have independently arrived at the same conclusion, which is that the agent shouldn't be the thing holding the credential.

Whether you build your own, adopt Agent Vault, or pick up something else entirely, the underlying principle holds: if an agent can't be trusted with credentials, it shouldn't have them. The proxy is just the cleanest way we've found to make that true in practice. If any of this resonates and you'd like to dig in further, give Agent Vault a look or reach out to the team; we'd love to compare notes with anyone building in this space.