OneCLI Review: The Sandboxed Agent Harness for Teams (YC S26)

OneCLI Review: The Sandboxed Agent Harness for Teams (YC S26)

A sandboxed agent harness is the layer that gives each AI agent its own isolated computer, routes every outbound request through a policy gateway, and injects credentials at the network boundary so the agent never holds a real key. OneCLI (YC Summer 2026, built by ChartDB Inc.) ships exactly that: one sandboxed agent per employee, all egress forced through a Rust gateway that enforces organization policy before a secret is ever decrypted. ...

September 30, 2026 · 22 min · baeseokjae
AI agent human oversight study: humans missed 1 in 3 threats approving AI agent commands

AI Agent Human Oversight: Why Humans Missed 1 in 3 Threats Approving Commands

When a human reviews an AI agent’s commands before they run, they miss roughly one in three threats. That is the headline finding of a study of more than 40,000 sessions and 409,000 individual approve-or-deny decisions, where players reviewed an AI coding agent’s shell commands under time pressure and achieved a mean accuracy of just 66.3%. The result is not a verdict on human competence — it is a verdict on a design pattern. Sustained vigilance is something humans are measurably bad at, and any security model that depends on it as the sole safeguard is built to fail. The fix is not better humans; it is better systems that layer sandboxing, scoped credentials, and surgical gating on top of human review. ...

September 3, 2026 · 10 min · baeseokjae
smolagents Python Executor Code Injection Guide 2026 (CVE-2026-4963)

smolagents Python Executor Code Injection Guide 2026 (CVE-2026-4963)

If you’re running Hugging Face’s smolagents in production with the local Python executor, stop what you’re doing and read this. CVE-2026-4963 is a code injection vulnerability in smolagents <= 1.25.0-dev.0 that lets an attacker execute arbitrary Python code on the host machine. The NVD rates it 10.0 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The exploit is public. And here’s the worst part — this is an incomplete fix for CVE-2025-9959, meaning the previous patch didn’t actually close the hole. ...

July 7, 2026 · 7 min · baeseokjae
AI Agent Security Tools 2026: Protecting Autonomous Agents in Production

AI Agent Security Tools 2026: Protecting Autonomous Agents in Production

Autonomous AI agents are executing real actions — writing code, querying databases, sending emails, and calling third-party APIs — and the security industry is finally treating them as the high-value attack surface they represent. The AI security market is projected to reach $12.8B by 2026 at a 28% CAGR, driven almost entirely by enterprise urgency around agent deployments. Unlike traditional software vulnerabilities, AI agent attacks are often semantic rather than syntactic: a well-crafted prompt in a retrieved document can silently redirect an agent’s entire task chain without triggering a single firewall rule. Security teams that treat agents like ordinary microservices will discover this difference the hard way. ...

May 15, 2026 · 17 min · baeseokjae