Here's a question I think we need to start asking when we give AI agents access to…
This is a dev post classified by Jev as Security (an opinion), kept by the Dev Radar because it carries real work, not commentary.
Here's a question I think we need to start asking when we give AI agents access to developer infrastructure: **What can it actually DO once it gets there?** Giving an agent access to GitHub, a package registry, CI/CD, a container registry, or cloud infrastructure isn't just "connecting a tool." You're giving it capabilities. Can it read? Write? Publish? Delete? Deploy? Access credentials? Change configuration? And does it actually need ALL of those permissions? The agent can decide what it wants to do. **It doesn't get to decide what it's allowed to do.** That's our job. I talke
Posted by Tanya Janca | Shehackspurple (50.3k followers) 1 h ago · 2 likes · 297 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.
More dev work like this
- Azure security gets complicated fast. — @AiswaryaVenkit1
- 平时觉得自己隐私保护得还行?其实偶尔做一次泄露自查也挺有必要。 — @bkdgiffug
- Applications today can pull thousands of third-party packages, and AI agents are… — @depthfirstlabs
- 以前拿 Claude Code 做安全研究,很多时候还是得自己一步步引导。 — @bkdgiffug
- Useful tool for cybersecurity researchers and red teamers. — @0x0SojalSec
- A malicious npm package was published with **completely valid provenance**. — @shehackspurple
- Grok @bot has a @1Password integration! You ask it to connect to your account, it… — @altryne
- Embedding a Gemini API key in client-side code can expose it to anyone using your app. — @freeCodeCamp
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 23.2k posts from 5k X accounts over the last 21 days, 2.7k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-24 02:51 UTC. Full method.