{"id":"2028483837496635809","url":"https://x.com/elvissun/status/2028483837496635809","text":"alright here’s every practical security tip i have on agents:\n\n- move critical data to a USB stick, unplug when sleeping\n- security by least privilege, not by prompts\n- billing cap on everything AI touches\n- limit reads of external data, wrap in <UNTRUSTED_EXTERNAL_CONTEXT> always\n- don’t post about what access your agent has publicly - those are prompt injection invitations (unless @levelsio already posted about it, then it’s a race)\n- don’t connect to moltbook (lol?)\n- roll every skill yourself\n- sandbox browser access\n- readonly prod access\n- allow prod writes only for specific use cases (i have /admin/zoe/* for zoe to handle support cases like credit topups)\n- one-time access for anything sensitive (eg gmail) with human in the loop, self-revoke access on script finish\n- create dedicated scripts, avoid improvised bash\n- use better models\n- audit trails everywhere -> security self-improvements\n\nmistakes will happen. limit worst case, embrace the rest","author":{"name":"Elvis","username":"elvissun","avatarUrl":"https://pbs.twimg.com/profile_images/1886389973236011008/7EZHFw9k_200x200.jpg"},"createdAt":"Mon Mar 02 14:53:28 +0000 2026","engagement":{"replies":61,"retweets":116,"likes":1737,"views":208906},"media":{"photos":[{"url":"https://pbs.twimg.com/media/HCafTEOaUAEWrwI.jpg?name=orig","width":3024,"height":4032}],"videos":[]},"quoteTweet":{"id":"2028299071903941056","url":"https://x.com/levelsio/status/2028299071903941056","text":"This guy has lots of great security tips if you're coding with AI, great follow @elvissun","author":{"name":"@levelsio","username":"levelsio","avatarUrl":"https://pbs.twimg.com/profile_images/2077111020305162240/PwddgOau_200x200.jpg"},"createdAt":"Mon Mar 02 02:39:17 +0000 2026"}}