frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Best practices for AI agent safety and privacy

2•mw1•11h ago
tl;dr looking for any links, resources or tips around best practices for data security, privacy, and agent guardrails when using Claude (or others).

My journey over the past few years has been one of borderline AI skeptic for its use in coding to having tried Claude Code a month ago and being unlikely to ever go back to coding big changes without it. Most queries I would have used search for in the past are now done in AI models as a first step.

However, one thing that concerns me is whether I am using best practices around agent safety and code protection. I have turned off the “Help improve Claude” toggle in the web panel for Claude settings. Do we believe that’s enough to really stop them (the companies who took any data they could find to make this tool) from using or training on our code? Are all the companies and people using this product just entrusting their proprietary code bases to these AI companies? Is it enough for me to be on the $20/mo Claude Pro plan or do I have to pony up for a Teams plan to protect my data? Which companies do we trust more in this space?

In terms of agent guardrails, I have set up Claude CLI on a cloud VPS Ubuntu host, as its own user that has access to read and modify the code, but no commit ability or git credentials or access to data on my personal machines. The repos are in a directory with group write access and then my personal user account does all commits and pushes, to ensure that Claude has no tangible way to destroy any data that isn’t backed up offsite in git. I don’t provide any of the environment variable credentials necessary to actually run the software, or access to any real data, so testing and QA is still something I do manually and pushing the changes to another machine.

I use it iteratively on individual features or bug fixes. I still have to go back and forth with it (or drop into my editor) a decent amount when it makes mistakes or to encourage better architectural decisions, but it is overall quite fun and exciting for me to use (at this early stage of learning and exploration) and seems to speed up development for my use case in a major way (solo dev SaaS site with web, iOS, and Android native apps + many little, half-finished side projects and ideas).

Does HN have any links or resources that round up the state of the art best practices around AI use for those who are cautious and not wanting to give it the keys to kingdom, but trying to take advantage of this new coding frontier in a safe way? What commands or settings would be typically considered safe to always allow so it doesn’t need to ask for permission as often? What security or privacy toggles do I want to consider in Claude (or other agents). Is it good to subscribe to a couple services and have one review the other’s code as a first step? I hit usage limits on the $20 Claude Pro, should I go to Max or spread horizontally across different AI models? Thanks for any tips!

Tell HN: Ralph Giles has died (Xiph.org| Rust@Mozilla | Ghostscript)

242•ffworld•11h ago•9 comments

SMTP server from scratch in Go – FSM, raw TCP, and buffer-oriented I/O

3•Jyotishmoy•1h ago•0 comments

Ask HN: What would you recommend a vibe coder learn about how all this works?

14•alexdobrenko•13h ago•14 comments

Ask HN: Why is my Claude experience so bad? What am I doing wrong?

4•moomoo11•2h ago•3 comments

Ask HN: Better hardware means OpenAI, Anthropic, etc. are doomed in the future?

3•kart23•6h ago•3 comments

Ask HN: Did YouTube change how it handles uBlock?

13•tefloon69•14h ago•7 comments

Ask HN: What are you working on? (February 2026)

327•david927•4d ago•1122 comments

Ask HN: Do sociotechnical pressures select for beneficial or harmful AI systems?

3•jerlendds•13h ago•1 comments

Who discovered grokking and why is the name hard to find?

2•asmodeuslucifer•4h ago•0 comments

Ask HN: What happens when capability decouples from credentials?

6•falsework•9h ago•3 comments

Ask HN: Tools to code using voice?

5•emerongi•20h ago•3 comments

Ask HN: How do you audit LLM code in programming languages you don't know?

5•syx•16h ago•5 comments

Ask HN: We're building a saving app for European savers and need GTM advice

3•AlePra00•13h ago•6 comments

Ask HN: If your OpenClaw could do 1 thing it currently can't, what would it be?

5•stosssik•11h ago•3 comments

Ask HN: How do founders demo real product without exposing sensitive data?

4•legitimate_key•12h ago•3 comments

Ask HN: How do you "step through" your own anxiety?

5•schneak•12h ago•7 comments

Ask HN: Are you using an agent orchestrator to write code?

30•gusmally•15h ago•45 comments

Ask HN: Would you use context-based "modes" in Instagram(work,study,sport,news)?

3•MatiasLaudonio•10h ago•2 comments

Ask HN: Why are electronics still so unrecyclable?

70•alexandrehtrb•1d ago•137 comments

Ask HN: How much PTO do you get?

2•SunshineTheCat•10h ago•6 comments

Ask HN: Best practices for AI agent safety and privacy

2•mw1•11h ago•0 comments

Ask HN: How to build text-to-app platforms?

2•desperado1•12h ago•1 comments

Ask HN: GPT-5.3-Codex being silently routed to GPT-5.2?

4•tardis_thad•13h ago•2 comments

Ask HN: What's the current state of ChatGPT Apps?

3•arthurlee•15h ago•1 comments

Ask HN: Has anyone achieved recursive self-improvement with agentic tools?

9•nycdatasci•1d ago•14 comments

Ask HN: Is Prettier extension working for you in Cursor?

2•vldszn•17h ago•0 comments

Ask HN: Anyone else get bricked by the macOS update?

2•bix6•18h ago•1 comments

Ask HN: Dumping GitHub for Forgejo for a free and open source project

4•th0th•20h ago•4 comments

Tell HN: GPT-5.3-codex is now available in the API

3•bigwheels•16h ago•0 comments

Ask HN: Why is everyone here so AI-hyped?

29•fandorin•2d ago•18 comments