Coding agents can run shell commands, install packages, call MCP tools and touch your…
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
Coding agents can run shell commands, install packages, call MCP tools and touch your secrets. Maybe we should watch them. 😂 Prismor is an open-source firewall for AI agents. Every tool call gets checked BEFORE it runs. Allow. Warn. Approve. Block. https://github.com/PrismorSec/prismor Codex + Hermes included.
Posted by Tony Simons (11.7k followers) 1 h ago · 5 likes · 542 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: prismor.
More dev work like this
- Congrats, Ananay! — @solofounders
- Hardening Linux's C Code: A Rewrite-and-Verify Loop — @rustaceans_rs
- At a certain scale, tracking who has access to what becomes a full-time job. — @mondaydotcom
- Here are 12 Appwrite Firewall rules that stop real attacks: — @appwrite
- AI security has plenty of benchmarks. — @OrcaRouter
- Agent permissions are easy to widen by accident. This repo keeps them task-scoped. — @DanKornas
- People still aren't getting it! So going to spell it out for you as to why you want this… — @PixelRainbowNFT
- Tbh this is pretty reasonable. Another axis of scaling: — @teortaxesTex
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 22.6k posts from 5k X accounts over the last 21 days, 2.6k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-23 16:31 UTC. Full method.