I Didn't Know Where My Keys Had Leaked, So I Started Building GuestSafe
After a compromised Mac and AI agents leaked secrets into session logs, I began building GuestSafe: a local, auditable alternative to .env.local.
4 articles
After a compromised Mac and AI agents leaked secrets into session logs, I began building GuestSafe: a local, auditable alternative to .env.local.
A field survey of local secret stores for AI agents on macOS—and the privilege boundary needed to keep an agent from erasing its own access trail.
A deep-dive security review of Claude Code's internals, reconstructed from its published source maps. Covers permission sandboxing, shell execution, credential handling, remote killswitches, and 10 findings.
Address poisoning isn't a user problem — it's a wallet UI bug. How wallets enable this $68M attack and how to fix it.