Skip to content
Back to writing

Security became a design problem

A useful agent can also become a very efficient way to mishandle client work.

  • Loopy
  • Trust boundaries

A security review found places where untrusted project content and powerful agent tools crossed the wrong boundary. I stopped treating that as somebody else's backend problem.

We tightened the runtime, reduced what agent processes could read, improved key handling, and made failure states close when something went wrong. If I want clients to put real product context into Loopy, protecting that context is part of the experience.