frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AI agent has more production access than your senior engineers

1•sallamzz92•1h ago
There’s a pattern I keep seeing across teams adopting AI agents for infrastructure, and it’s starting to scare me.

A team sets up an agent to help with Terraform, Kubernetes configs, or cloud deployments. To make it useful, they give it cloud credentials, state files, sometimes CI/CD pipeline access. They test it in staging. It works. They move it to production. Nobody asks: what’s the blast radius if this thing gets prompt-injected?

Coding agents are not infrastructure agents.

The industry is conflating these two categories. We treat all AI agents as “AI-assisted development” and apply the same security model. But the threat surfaces are completely different.

A coding agent operates in a sandbox (your IDE), produces artifacts that get reviewed (PRs), and has a natural checkpoint (CI/CD). An infrastructure agent operates on live systems, produces changes that take effect immediately, and often has no checkpoint at all.

Using the same word “agent” for both is making us less safe. It lets teams apply their comfort with Copilot to justify comfort with an agent that has kubectl apply access to production.

The superuser-by-default problem.

In most setups I’ve seen, the AI agent inherits whatever credentials the developer has. Broad IAM roles created for human operators who exercise judgment. The agent doesn’t exercise judgment. It exercises permissions.

Your senior engineer has admin access but uses it carefully. Your AI agent has the same access and uses it indiscriminately. No concept of blast radius, no intuition about risk, no career on the line.

From a MITRE ATT&CK perspective, a single prompt injection on an infra agent with broad permissions gives you: credential access (read env vars), lateral movement (access other services), impact (modify/delete resources), and exfiltration (make network requests). Four major tactics from one vulnerability.

The convergence gap.

Even when an agent does the right thing, there’s a gap between the mutation it performs and convergence to a known-good state. Kubernetes controllers reconcile. Terraform plans drift. During that window, your infrastructure is in an unknown state, and the only entity that knows the intended state is the agent that made the change.

If the agent hallucinated, nobody knows intended state. If the agent got injected, the attacker knows and you don’t. This is the unsolved hard problem in agentic infrastructure.

What works: constrain before you automate.

Teams handling this well define explicit permission boundaries: which resources, which actions, which conditions. They require human approval for irreversible actions. They log every mutation with intent alongside action. They continuously compare actual state to intended state.

The exercise: if your agent got prompt-injected right now, what is the worst thing it could do with the credentials it actually has?

If the answer scares you, you have a permissions problem. The solution is not to stop using agents. It is to constrain them like any other service with production access: least privilege, audit trails, blast radius containment.

We are building tools for this at Stakpak (stakpak.dev). But even before tooling, just asking that question is the most important first step.

Ask HN: How do you manage flaky E2E tests at scale?

1•forcepushed•1m ago•0 comments

Ask HN: What do you think about the recent Slack UI change?

1•1e1a•3m ago•0 comments

America's Broken Psych Ward Model: The Solution Nature Affords

https://ccmarieclark.substack.com/p/americas-broken-psych-ward-model
1•exolymph•4m ago•0 comments

Google Cloud Telemetry (OTLP) API Overview

https://docs.cloud.google.com/stackdriver/docs/reference/telemetry/overview
1•tosh•4m ago•0 comments

Adding Fediverse Comments to Pelican Blog

https://blog.hofstede.it/adding-fediverse-comments-to-a-pelican-blog/
2•vermaden•5m ago•0 comments

Ask HN: Ever design a product similar to one from AWS?

1•a_lifters_life•6m ago•0 comments

Google sent personal and financial information of student journalist to ICE

https://techcrunch.com/2026/02/10/google-sent-personal-and-financial-information-of-student-journ...
1•pseudolus•7m ago•0 comments

Travel planning is broken. broken

https://www.govialo.com/
1•CuylerM•8m ago•1 comments

Show HN: Video Forms – turn any YouTube video into an interactive questionnaire

https://vforms.bevel.software/
1•juanviera23•10m ago•0 comments

Nature's 'engine is grinding to a halt' as climate change gains pace

https://phys.org/news/2026-02-nature-halt-climate-gains-pace.html
3•bikenaga•12m ago•1 comments

Something Big Is Happening

https://twitter.com/mattshumer_/status/2021256989876109403
2•matthewsinclair•15m ago•1 comments

The smallest insects evolve anucleate neurons [pdf]

https://gbragafibra.github.io/papers/Polilov2012_wasp_neurons.pdf
1•Fibra•18m ago•0 comments

Scrap Labs – Metal 3D Printer

https://www.scraplabs3d.com/
1•cgg1•19m ago•0 comments

Collio is Live – your co-worker is here

https://collio.chat/
1•serin-ai•19m ago•1 comments

Patch Tuesday, February 2026 Edition

https://krebsonsecurity.com/2026/02/patch-tuesday-february-2026-edition/
1•todsacerdoti•19m ago•0 comments

Ask HN: What makes early-stage AI accelerators useful (and what doesn't)?

1•rdi_berkeley•20m ago•0 comments

Instantspaces – Remove space switching animation on macOS

https://github.com/flawnn/instantspaces
2•flawn•21m ago•0 comments

Go 1.26 Introduces Two Language Changes, New Performance Improvements

https://www.phoronix.com/news/Go-1.26-Released
1•mikece•23m ago•0 comments

Waku: The Minimal React Framework Reaches Alpha

https://www.infoq.com/news/2026/02/waku-react-framework/
1•mikece•24m ago•0 comments

The Singularity Is Always Near

https://kevinkelly.substack.com/p/the-singularity-is-always-near
1•lbrito•26m ago•0 comments

Discord clarifies approach to age assurance

https://discord.com/safety/how-discord-is-building-safer-experiences-for-teens
1•dm•26m ago•0 comments

Hacker News Alternative Where People Are Positive About AI

4•dunk010•26m ago•7 comments

Show HN: Berkeley Xcelerator – early-stage AI and agentic AI accelerator

https://rdi.berkeley.edu/xcelerator
1•rdi_berkeley•27m ago•0 comments

5-century tree-ring record reveals intensification of West Mediterranean storms

https://cp.copernicus.org/articles/21/2205/2025/
1•PaulHoule•28m ago•0 comments

Russia Further Restricts Telegram, Escalating Internet Clampdown

https://www.nytimes.com/2026/02/10/world/europe/telegram-throttled-internet-russia.html
1•jbegley•28m ago•0 comments

Private RAG and marketplace to sell your knowledge to AI agents

https://ragora.app
1•mregmi405•31m ago•1 comments

Debugging random slow writes with GIN indexes in PostgreSQL

https://iamsafts.com/posts/postgres-gin-performance/
2•fanf2•34m ago•1 comments

FOSDEM 2026: RISC-V Hardware Is Here. What About Software? [video]

https://fosdem.org/2026/schedule/event/983NCX-what-about-riscv-software/
1•pjmlp•36m ago•0 comments

The Future of the Global Open-Source AI Ecosystem: From DeepSeek to AI+

https://huggingface.co/blog/huggingface/one-year-since-the-deepseek-moment-blog-3
2•mariuz•36m ago•0 comments

Ask HN: What useful knowledge do you have that LLMs don't?

1•toephu2•36m ago•1 comments