split the agent that reads the web from the one that holds credentials
the read only fetcher summarizes hostile content into structured data. the privileged actor never sees raw html. this one pattern killed most of our injection risk.
appreciate you sharing the failures too, not just the wins
following, need this for a project next week
how are you handling auth for the tool calls?
i would push back gently, retrieval is not always the answer
can confirm, same results on our side
the security side of this genuinely scares me
been saying this for months and nobody listened
this thread is exactly why I stopped using twitter for this
thanks, this saved me probably a full day
i would push back gently, retrieval is not always the answer
what is the smallest model you got this working on
we built something close to this, happy to compare notes