<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: AgentGuard</title>
    <description>The latest articles on DEV Community by AgentGuard (@agentguard).</description>
    <link>https://dev.to/agentguard</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4116143%2F033375f9-98c7-4543-a5d2-f9dc7afab6d4.jpg</url>
      <title>DEV Community: AgentGuard</title>
      <link>https://dev.to/agentguard</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/agentguard"/>
    <language>en</language>
    <item>
      <title>Meine Claude-Code-Quota ist zweimal pro Woche gestorben. Ich habe ein Forensik-Tool geschrieben, um herauszufinden, warum.</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Tue, 15 Sep 2026 03:14:05 +0000</pubDate>
      <link>https://dev.to/agentguard/meine-claude-code-quota-ist-zweimal-pro-woche-gestorben-ich-habe-ein-forensik-tool-geschrieben-um-397l</link>
      <guid>https://dev.to/agentguard/meine-claude-code-quota-ist-zweimal-pro-woche-gestorben-ich-habe-ein-forensik-tool-geschrieben-um-397l</guid>
      <description>&lt;p&gt;Meine Claude-Code-Quota verbrennt schnell — und die Zähler haben es nie erklärt. Sie beantworten wie viel. Nicht wo, nicht&lt;br&gt;
    warum.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Also habe ich ein Skript auf meine lokalen Session-Transkripte (~/.claude/projects/**/*.jsonl) losgelassen und angefangen    
zu graben. Daraus ist ein Tool geworden: quota-autopsy.                                                                      

Also habe ich ein Skript auf meine lokalen Session-Transkripte (~/.claude/projects/**/*.jsonl) losgelassen und angefangen    
zu graben. Daraus ist ein Tool geworden: quota-autopsy.                                                                      

Was die Daten wirklich zeigten (46 meiner Sessions)                                                                          

• 1.162 eindeutige API-Calls, 276,58M Tokens ≈ $187,80                                                                       
• ≈ $10,47 waren vermeidbar — genau diese Zahl sagen dir Zähler nie                                                          
• 4 warme Kontexte ungecacht neu gesendet (≈ $3,39), wiederholte Datei-Reads (≈ $2,39), überdimensionierte Tool-Outputs (≈   
$4,69)                                                                                                                       
• Eine Session hat nach 15 Stunden Pause 610,5k frische Tokens neu gesendet — $3,08 fürs reine Nichtstun                     

Die Muster, die es findet                                                                                                    

1. Cache-Re-Creates — das gecachte Präfix wird neu geschrieben, obwohl es noch frisch ist. Ein Cache-Bust kostet das         
12,5-Fache eines Cache-Hits — und Claude Code macht es lautlos.                                                              
2. Warme Re-Sends — ein Call liest null aus dem Cache, Sekunden nach einem Full-Context-Call.                                
3. TTL-Downgrades — Cache-Writes kippen mitten in der Session von 1 h auf 5 min.                                             
4. Bezahlter Bloat — 600KB-Terminal-Dumps, die jede weitere Runde den Kontext aufblähen.                                     
5. Doppelzählung durch Session-Splits — Dedupe per message.id hat 3.600 Duplikat-Zeilen kollabiert; naive Parser lägen ~40    
% daneben.                                                                                                                   

Warum ich den Zahlen vertraue                                                  

• Token-Zahlen exakt (Streaming-Teile per API-Response-ID dedupliziert)                                                      
• Dollar-Schätzungen gegen Claude Codes eigene cost-state-Einträge gegengeprüft                                              
• Unabhängige zweite Implementierung rechnet jede Metrik nach (45/45 Tests grün)                                             
• Zu 100 % lokal — null Dependencies, keine Telemetrie, kein Account                                                         

Ausprobieren                                                                                                                 

  ─ bash                                                                                                                
  npx quota-autopsy                                                                                                          

Kostenloser Überblick für alle. Pro ($24, lebenslang) schaltet die Session-Autopsie frei — jeder Befund mit exaktem Turn     
und Fixes. Model-agnostisch (editierbare Preis-Tabelle für jeden Provider).                                                  

Website: https://quota-autopsy.pro — Fragen beantworte ich gern in den Kommentaren.     
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

</description>
      <category>claude</category>
      <category>ai</category>
      <category>webdev</category>
      <category>infrastructure</category>
    </item>
    <item>
      <title>My Claude Code quota died twice a week. I wrote a forensics tool to find out why.</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Tue, 15 Sep 2026 03:12:05 +0000</pubDate>
      <link>https://dev.to/agentguard/my-claude-code-quota-died-twice-a-week-i-wrote-a-forensics-tool-to-find-out-why-3jmi</link>
      <guid>https://dev.to/agentguard/my-claude-code-quota-died-twice-a-week-i-wrote-a-forensics-tool-to-find-out-why-3jmi</guid>
      <description>&lt;p&gt;I burn through Claude Code quota fast — and the counters never explained it. They answer how much. Not where, not why.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;So I pointed a script at my local session transcripts (~/.claude/projects/**/*.jsonl) and started digging. Then I turned it
into a tool: quota-autopsy.                                                                                                  

What the data actually showed (46 of my sessions)                                                                            

• 1,162 unique API calls, 276.58M tokens ≈ $187.80
• ≈ $10.47 was avoidable — that's the number counters never tell you                                                         
• 4 warm contexts re-sent uncached (≈ $3.39), repeated file reads (≈ $2.39), oversized tool outputs (≈ $4.69)
• One session re-sent 610.5k fresh tokens after a 15h idle gap — $3.08 for doing literally nothing                           

The mechanisms it finds                                                                                                      

1. Cache re-creates — the cached prefix gets rewritten while still fresh. A cache read costs 0.1×, a cache write 1.25×. A  
cache-bust costs 12.5× a cache hit, and Claude Code does it silently.
2. Warm re-sends — a call reading zero from cache, seconds after a full-context call. Two full-context bills back-to-back.   
3. TTL downgrades — cache writes shifting from 1h to 5m mid-session (the documented post-quota penalty).                     
4. Paid bloat — 600KB terminal dumps and screenshots re-inflating context on every later turn.                               
5. Session-split double counting — dedupe by message.id collapsed 3,600 duplicate rows in my corpus. Naive parsers           
over-count by ~40%.                                                                                                          

Why I trust the numbers                                                                                                      

• Token counts exact (streaming partials deduped by API response id)
• Dollar estimates cross-checked against Claude Code's own cost-state rows                                                   
• Independent second implementation recomputes every metric (45/45 tests green)
• 100% local — zero dependencies, no telemetry, no account                                                                   

Try it                                                                                                                       

  ─ bash           
  npx quota-autopsy                                                                                                          

Free overview for everyone. Pro ($24, lifetime) unlocks the per-session autopsy with exact turns and fixes. Model-agnostic
(editable pricing table for any provider/router).                                                                            

Website: https://quota-autopsy.pro — happy to answer questions in the comments.  
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

</description>
      <category>ai</category>
      <category>webdev</category>
      <category>programming</category>
      <category>infrastructure</category>
    </item>
    <item>
      <title>AgentGuard Update: Open Core, Break-Glass Governance — and the First Real-World Finds</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Wed, 09 Sep 2026 19:54:24 +0000</pubDate>
      <link>https://dev.to/agentguard/agentguard-update-open-core-break-glass-governance-and-the-first-real-world-finds-fnp</link>
      <guid>https://dev.to/agentguard/agentguard-update-open-core-break-glass-governance-and-the-first-real-world-finds-fnp</guid>
      <description>&lt;p&gt;When I posted the launch here on dev.to, the pitch was simple: I attacked my own repo — and my own PR bot blocked the attack before merge. A lot has moved since then. Here's the honest update, including the uncomfortable parts.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Open-Core Split: The Line Is Now Public
&lt;/h2&gt;

&lt;p&gt;AgentGuard has been two clearly separated parts since this week:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Public (MIT):&lt;/strong&gt; the deterministic engine with 12 rule classes and the free GitHub Action — 59 tests, every one of them publicly traceable.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Private:&lt;/strong&gt; the Pro components — GitHub App server with check-run gate, multi-tenant, rules editor, re-sharpening, and billing — 26 more tests.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Why the split? Because a CI gate for coding agents is either a hobby or a product. I chose the latter. The community loses nothing: the engine stays MIT, the Action stays free for public repos. The line is documented in &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/LICENSING.md" rel="noopener noreferrer"&gt;LICENSING.md&lt;/a&gt; — in plain text, not fine print.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Break-Glass Governance: Exceptions That Can't Hide
&lt;/h2&gt;

&lt;p&gt;Every honest security policy needs exceptions. The naive version is the permanent bypass: switch it off once, it stays off forever. Our answer in v0.2.2:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;waiver is an issue&lt;/strong&gt; — an immutable record of who exempted what, and when.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mandatory reviewer&lt;/strong&gt;, &lt;strong&gt;max. 30 days lifetime&lt;/strong&gt;, &lt;strong&gt;automatic expiry&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;guardian workflow&lt;/strong&gt; runs weekly, comments on expired exceptions, and files a warning issue.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;And here's the part that matters to me: we don't claim the expiry works — we demonstrate it publicly. A test waiver (&lt;a href="https://github.com/agentguard-dev/agentguard/issues/13" rel="noopener noreferrer"&gt;#13&lt;/a&gt;) runs in our own repo and expires automatically on &lt;strong&gt;16 Sep 2026&lt;/strong&gt;. The guardian run after that documents it publicly: commented, warned, closed. That's the difference between a policy on paper and one that proves itself. For your own repo: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/BREAK-GLASS.md" rel="noopener noreferrer"&gt;break-glass policy&lt;/a&gt;, &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/ADR-002-break-glass-governance.md" rel="noopener noreferrer"&gt;ADR-002&lt;/a&gt;, &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/workflow-templates/break-glass-guard.yml" rel="noopener noreferrer"&gt;workflow template&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. 85 Tests, Self-Scan in Our Own CI
&lt;/h2&gt;

&lt;p&gt;The full suite has grown to &lt;strong&gt;85 tests&lt;/strong&gt;: 59 in the public engine repo, 26 in the Pro repo. Still deterministic, still no LLM in the scan path. And still dogfooding: the scan of our own repo runs in our own CI — every landing page change has to pass our own gate first. That exact setup has already blocked one of our own PRs. Working as designed; it's all in the &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/CHANGELOG.md" rel="noopener noreferrer"&gt;changelog&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. The First Real-World Finds
&lt;/h2&gt;

&lt;p&gt;Two active open-source repos, two invisible characters:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;A &lt;strong&gt;zero-width space (U+200B)&lt;/strong&gt; directly before a bash block in an agent-facing spec.&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;U+200B&lt;/strong&gt; in the middle of a skill spec.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Invisible in every diff and every review — but a different file for the model than for the human reading it. That's the documented invisibility trick, not a theoretical scenario. Both finds are byte-verified and were responsibly disclosed to the maintainers — &lt;strong&gt;with no public naming&lt;/strong&gt;. If the maintainers want, there will be an update here.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. What Pro Does — and What It Costs
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;App server:&lt;/strong&gt; PR comment + check-run gate per repo, multi-tenant.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rules editor:&lt;/strong&gt; your own rules as a file, fail-closed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Re-sharpening:&lt;/strong&gt; generate new rules from real findings.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Billing:&lt;/strong&gt; Stripe checkout, fully wired.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Prices unchanged: &lt;strong&gt;Free&lt;/strong&gt;, &lt;strong&gt;Pro $19/repo/month&lt;/strong&gt;, &lt;strong&gt;Audit $499&lt;/strong&gt; (one-time), &lt;strong&gt;RedTeam $499/quarter&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try It
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;🛒 &lt;a href="https://github.com/marketplace/actions/agentguard-security" rel="noopener noreferrer"&gt;Free Action on the Marketplace&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🔴 &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;Live demo: planted attack, red check, no merge&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🌐 &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;Landing page&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📝 &lt;a href="https://github.com/agentguard-dev/agentguard/issues/new?template=audit-request.yml&amp;amp;labels=audit-request" rel="noopener noreferrer"&gt;Free first scan / Pro trial&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📦 &lt;a href="https://github.com/agentguard-dev/agentguard" rel="noopener noreferrer"&gt;Code&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>devops</category>
      <category>agents</category>
      <category>opensource</category>
    </item>
    <item>
      <title>AgentGuard Update: Open Core, Break-Glass-Governance — und die ersten echten Funde</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Wed, 09 Sep 2026 19:52:54 +0000</pubDate>
      <link>https://dev.to/agentguard/agentguard-update-open-core-break-glass-governance-und-die-ersten-echten-funde-2m10</link>
      <guid>https://dev.to/agentguard/agentguard-update-open-core-break-glass-governance-und-die-ersten-echten-funde-2m10</guid>
      <description>&lt;p&gt;Beim Launch hier auf dev.to war der Pitch einfach: Ich habe mein eigenes Repo angegriffen — und mein eigener PR-Bot hat den Angriff vor dem Merge geblockt. Seitdem ist einiges passiert. Das ehrliche Update, inklusive der unbequemen Teile.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Open-Core-Split: Die Grenze ist öffentlich sichtbar
&lt;/h2&gt;

&lt;p&gt;AgentGuard besteht seit dieser Woche aus zwei klar getrennten Teilen:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Öffentlich (MIT):&lt;/strong&gt; die deterministische Engine mit 12 Regelklassen und die Free GitHub Action — 59 Tests, jeder einzelne öffentlich nachvollziehbar.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privat:&lt;/strong&gt; die Pro-Komponenten — GitHub-App-Server mit Check-Run-Gate, Multi-Tenant, Regel-Editor, Re-Sharpening und Billing — 26 weitere Tests.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Warum der Split? Weil ein CI-Gate für Coding-Agents entweder ein Hobby ist oder ein Produkt. Ich habe mich für Letzteres entschieden. Die Community verliert dabei nichts: Die Engine bleibt MIT, die Action bleibt kostenlos für öffentliche Repos. Die Trennlinie steht in &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/LICENSING.md" rel="noopener noreferrer"&gt;LICENSING.md&lt;/a&gt; — bewusst im Klartext, nicht im Kleingedruckten.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Break-Glass-Governance: Ausnahmen, die sich nicht verstecken können
&lt;/h2&gt;

&lt;p&gt;Jede ehrliche Security-Policy braucht Ausnahmen. Die naive Variante ist der Dauer-Bypass: einmal aus, für immer aus. Unsere Antwort in v0.2.2:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Ein &lt;strong&gt;Waiver ist ein Issue&lt;/strong&gt; — ein unveränderlicher Beleg, wer wann was ausgenommen hat.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pflicht-Reviewer&lt;/strong&gt;, &lt;strong&gt;max. 30 Tage Laufzeit&lt;/strong&gt;, &lt;strong&gt;automatischer Ablauf&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Ein &lt;strong&gt;Guardian-Workflow&lt;/strong&gt; läuft wöchentlich, kommentiert abgelaufene Ausnahmen und erstellt ein Warn-Issue.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Und jetzt der Teil, der mir wichtig ist: Wir behaupten den Ablauf nicht — wir führen ihn öffentlich vor. In unserem eigenen Repo läuft ein Test-Waiver (&lt;a href="https://github.com/agentguard-dev/agentguard/issues/13" rel="noopener noreferrer"&gt;#13&lt;/a&gt;), der am &lt;strong&gt;16.09.2026&lt;/strong&gt; automatisch verfällt. Der Guardian-Lauf danach dokumentiert öffentlich: kommentiert, gewarnt, geschlossen. Das ist der Unterschied zwischen einer Policy auf Papier und einer, die sich selbst beweist. Für dein eigenes Repo: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/BREAK-GLASS.md" rel="noopener noreferrer"&gt;Break-Glass-Policy&lt;/a&gt;, &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/ADR-002-break-glass-governance.md" rel="noopener noreferrer"&gt;ADR-002&lt;/a&gt;, &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/workflow-templates/break-glass-guard.yml" rel="noopener noreferrer"&gt;Workflow-Template&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. 85 Tests, Self-Scan in der eigenen CI
&lt;/h2&gt;

&lt;p&gt;Die Gesamtsuite ist auf &lt;strong&gt;85 Tests&lt;/strong&gt; gewachsen: 59 im öffentlichen Engine-Repo, 26 im Pro-Repo. Weiterhin deterministisch, weiterhin kein LLM im Scan-Pfad. Und weiterhin Dogfooding: Der Scan unseres eigenen Repos läuft in unserer eigenen CI — jede Landingpage-Änderung muss zuerst am eigenen Gate vorbei. Genau das hat uns schon einmal den eigenen PR geblockt. Funktioniert wie designed, steht im &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/CHANGELOG.md" rel="noopener noreferrer"&gt;Changelog&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Die ersten echten Funde
&lt;/h2&gt;

&lt;p&gt;Zwei aktive Open-Source-Repos, zwei unsichtbare Zeichen:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Ein &lt;strong&gt;Zero-Width Space (U+200B)&lt;/strong&gt; direkt vor einem Bash-Block in einer agent-gelesenen Spec.&lt;/li&gt;
&lt;li&gt;Ein &lt;strong&gt;U+200B&lt;/strong&gt; mitten in einer Skill-Spec.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Unsichtbar in jedem Diff und in jedem Review — aber für das Modell eine andere Datei als für den Menschen. Das ist der dokumentierte Unsichtbarkeits-Trick, kein theoretisches Szenario. Beide Funde sind byte-verifiziert und wurden verantwortungsvoll an die Maintainer gemeldet — &lt;strong&gt;ohne öffentliche Namensnennung&lt;/strong&gt;. Falls die Maintainer es wünschen, gibt es hier ein Update.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Was Pro kann — und was es kostet
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;App-Server:&lt;/strong&gt; PR-Kommentar + Check-Run-Gate pro Repo, Multi-Tenant.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Regel-Editor:&lt;/strong&gt; eigene Regeln als Datei, fail-closed.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Re-Sharpening:&lt;/strong&gt; aus echten Befunden neue Regeln generieren.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Billing:&lt;/strong&gt; Stripe-Checkout, fertig verdrahtet.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Preise unverändert: &lt;strong&gt;Free&lt;/strong&gt;, &lt;strong&gt;Pro $19/Repo/Monat&lt;/strong&gt;, &lt;strong&gt;Audit $499&lt;/strong&gt; (einmalig), &lt;strong&gt;RedTeam $499/Quartal&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Probier es aus
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;🛒 &lt;a href="https://github.com/marketplace/actions/agentguard-security" rel="noopener noreferrer"&gt;Free Action im Marketplace&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🔴 &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;Live-Demo: gepflanzter Angriff, roter Check, kein Merge&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;🌐 &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;Landingpage&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📝 &lt;a href="https://github.com/agentguard-dev/agentguard/issues/new?template=audit-request.yml&amp;amp;labels=audit-request" rel="noopener noreferrer"&gt;Kostenloser Erst-Scan / Pro-Trial&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;📦 &lt;a href="https://github.com/agentguard-dev/agentguard" rel="noopener noreferrer"&gt;Code&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>security</category>
      <category>opensource</category>
      <category>devops</category>
      <category>ai</category>
    </item>
    <item>
      <title>Ich habe mein eigenes Repo angegriffen — mein PR-Bot hat den Angriff selbst blockiert</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Wed, 09 Sep 2026 03:03:26 +0000</pubDate>
      <link>https://dev.to/agentguard/ich-habe-mein-eigenes-repo-angegriffen-mein-pr-bot-hat-den-angriff-selbst-blockiert-3cfo</link>
      <guid>https://dev.to/agentguard/ich-habe-mein-eigenes-repo-angegriffen-mein-pr-bot-hat-den-angriff-selbst-blockiert-3cfo</guid>
      <description>&lt;p&gt;Coding-Agents sind die neue Benchmark für Dev-Teams: Claude Code, Cursor, Codex &amp;amp; Co. lesen dein Repo — und &lt;strong&gt;vertrauen ihm&lt;/strong&gt;. Ich habe mich gefragt: Was passiert, wenn jemand eine Anweisung ins Repo schmuggelt, die der Agent bereitwillig ausführt?&lt;/p&gt;

&lt;p&gt;Also habe ich &lt;strong&gt;AgentGuard&lt;/strong&gt; gebaut — ein CI-Gate für Agent-Konfigurationen (AGENTS.md, Skills, MCP-Server, Hooks). Und ich habe mein eigenes Repo mit 12 gezielten Angriffen bestückt. Das ehrliche Protokoll:&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Die Angriffe waren leicht zu verstecken
&lt;/h2&gt;

&lt;p&gt;12 Payloads: eine versteckte Instruction-Override-Anweisung in der AGENTS.md, unsichtbare Zero-Width-Zeichen in einer Skill-Datei, ein typ-squatted MCP-Server-Host, ein Hook, der Netzwerk-Inhalt in eine Shell piped, ein committeter API-Key, ein Agent mit wildem Bash-Zugriff … &lt;strong&gt;Jeder davon wirkt in einem PR-Review völlig normal.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;AgentGuard erkennt alle 12 — &lt;strong&gt;deterministisch&lt;/strong&gt;, ohne LLM im Scan-Pfad — mit &lt;strong&gt;47 Unit-Tests&lt;/strong&gt;, die das für immer beweisen (12/12 erkannt, 0 False Positives im sauberen Kontroll-Repo).&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Der Realitätscheck: 30 Repos, 5 mit kritischen Befunden
&lt;/h2&gt;

&lt;p&gt;Ich habe 30 öffentliche Repos über die GitHub-Code-Suche nach AGENTS.md gescannt — darunter Google, Microsoft und Nextcloud. &lt;strong&gt;5 mit kritischen Befunden.&lt;/strong&gt; Der spannendste: ein unsichtbares Zeichen direkt vor einem Bash-Block in einer Agenten-Spec. Zufall oder Absicht? Genau dafür ist das Tool da. Jeder Befund wurde manuell byte-genau geprüft und ist öffentlich: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md" rel="noopener noreferrer"&gt;Echtwelt-Befunde&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Doppeltes Dogfooding
&lt;/h2&gt;

&lt;p&gt;Zwei Dinge passierten, die ich nicht besser hätte inszenieren können:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;(a)&lt;/strong&gt; GitHubs eigene Push-Protection blockierte einen meiner Pushes — ein &lt;strong&gt;Fake-Token in meiner eigenen Testdatei&lt;/strong&gt; löste &lt;code&gt;GH013: Push cannot contain secrets&lt;/code&gt; aus. Der größte Code-Host der Welt hat an &lt;em&gt;meinem&lt;/em&gt; Repo demonstriert, was AgentGuard bei &lt;em&gt;deinem&lt;/em&gt; fängt.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;(b)&lt;/strong&gt; Wochen später, nach dem v0.2.1-Bypass-Schutz, &lt;strong&gt;blockierte unser eigenes Gate unseren eigenen Pull-Request&lt;/strong&gt; beim Selbsttest — die neue Regel ignoriert jede &lt;code&gt;.agentguard-ignore&lt;/code&gt;, die in einem PR mitgeliefert wird, und unser Selbsttest-Workflow hatte sich auf das alte Verhalten verlassen. Roter Check. Merge verweigert. Funktioniert wie designed. Die ganze Geschichte steht im &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/CHANGELOG.md" rel="noopener noreferrer"&gt;Changelog&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Gestern hat mein eigenes Sicherheits-Tool meinen eigenen Pull-Request geblockt. Das ist die beste Demo, die ein Sicherheitsprodukt haben kann.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Was in v0.2.1 kam
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fail-closed Gates:&lt;/strong&gt; Ein Tippfehler in &lt;code&gt;exit-on&lt;/code&gt; deaktiviert das Gate nicht mehr still — es bricht laut ab.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PR-Bypass-Schutz:&lt;/strong&gt; Eine im PR mitgelieferte &lt;code&gt;.agentguard-ignore&lt;/code&gt; wird ignoriert; Ausnahmen kommen nur aus dem vertrauenswürdigen Workflow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Gehärteter Pro-Server:&lt;/strong&gt; HMAC-Längenprüfung, 1-MB-Webhook-Body-Limit, Installation pro Repo, sicheres Tarball-Entpacken (Größenlimit, Symlink-/Traversal-Abweisung).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Neue Secret-Muster:&lt;/strong&gt; Private Keys, GitHub-PATs, npm, Stripe, Slack-Webhooks. Details in &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/SECURITY.md" rel="noopener noreferrer"&gt;SECURITY.md&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. Der Bot blockierte einen Angriff live
&lt;/h2&gt;

&lt;p&gt;Die GitHub-App kommentiert jeden PR mit Note und Befunden und setzt ein Check-Run-Gate. Der Beweis ist ein echter Pull-Request: Ein gepflanzter Angriff bekam &lt;strong&gt;Note E, einen roten Check und keinen Merge&lt;/strong&gt; — &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;live ansehen&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. Die Landingpage zeigt jetzt den Moment
&lt;/h2&gt;

&lt;p&gt;Die &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;Landingpage&lt;/a&gt; hat ein Live-Scan-Terminal im Hero: Es tippt sich durch Dateien, findet die gepflanzte Anweisung und endet im grünen &lt;strong&gt;MERGE-GEBLOCKT&lt;/strong&gt;-Moment — genau das Gefühl, das dieses Produkt verkauft: &lt;em&gt;Dein Agent liest dein Repo. Dein Gate liest mit.&lt;/em&gt; Gemessene Qualität statt Deko: Lighthouse 100/100/100/100 auf Desktop und Mobile, LCP 179 ms, CLS ~0, kein Horizontal-Scroll bis 320 px.&lt;/p&gt;

&lt;h2&gt;
  
  
  Probier es aus
&lt;/h2&gt;

&lt;p&gt;MIT-lizenziert, kostenlos für öffentliche Repos auf dem GitHub Marketplace. Schick dein Repo und bekomm einen kostenlosen Erst-Scan — oder stell die Anfrage direkt: &lt;a href="https://github.com/agentguard-dev/agentguard/issues/new?template=audit-request.yml&amp;amp;labels=audit-request" rel="noopener noreferrer"&gt;Audit/Trial/RedTeam-Formular&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;🔗 Code: &lt;a href="https://github.com/agentguard-dev/agentguard" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard&lt;/a&gt;&lt;br&gt;
🛒 Marketplace: &lt;a href="https://github.com/marketplace/actions/agentguard-security" rel="noopener noreferrer"&gt;https://github.com/marketplace/actions/agentguard-security&lt;/a&gt;&lt;br&gt;
📊 Verifizierte Befunde: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md&lt;/a&gt;&lt;br&gt;
🔴 Live-Demo (Angriff geblockt): &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard-demo/pull/2&lt;/a&gt;&lt;br&gt;
🌐 Landingpage: &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;https://agentguard-dev.github.io/agentguard/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>devops</category>
      <category>agents</category>
    </item>
    <item>
      <title>I attacked my own repo — my PR bot blocked the attack before merge</title>
      <dc:creator>AgentGuard</dc:creator>
      <pubDate>Tue, 08 Sep 2026 16:49:35 +0000</pubDate>
      <link>https://dev.to/agentguard/i-attacked-my-own-repo-my-pr-bot-blocked-the-attack-before-merge-4fio</link>
      <guid>https://dev.to/agentguard/i-attacked-my-own-repo-my-pr-bot-blocked-the-attack-before-merge-4fio</guid>
      <description>&lt;p&gt;Coding agents are the new benchmark for dev teams: Claude Code, Cursor, Codex &amp;amp; Co. read your repo — and &lt;strong&gt;trust it&lt;/strong&gt;. I asked myself: what happens when someone smuggles an instruction into the repo that the agent happily executes?&lt;/p&gt;

&lt;p&gt;So I built &lt;strong&gt;AgentGuard&lt;/strong&gt; — a CI gate for agent configurations (AGENTS.md, skills, MCP servers, hooks). And I stuffed my own repo with 12 targeted attacks. The honest protocol:&lt;/p&gt;

&lt;h2&gt;
  
  
  1. The attacks were easy to hide
&lt;/h2&gt;

&lt;p&gt;12 payloads: a hidden instruction-override in AGENTS.md, invisible zero-width characters in a skill file, a typo-squatted MCP server host, a hook piping network content into a shell, a committed API key, an agent with wild Bash access… Every single one looks normal in a PR review.&lt;/p&gt;

&lt;p&gt;AgentGuard detects all 12 — &lt;strong&gt;deterministically&lt;/strong&gt;, no LLM in the scan path — with &lt;strong&gt;47 unit tests&lt;/strong&gt; that prove it forever (12/12 detected, 0 false positives on the clean control repo).&lt;/p&gt;

&lt;h2&gt;
  
  
  2. The real-world run: 30 repos, 5 with critical findings
&lt;/h2&gt;

&lt;p&gt;I scanned 30 public repos via GitHub's code search for AGENTS.md — including Google, Microsoft and Nextcloud. &lt;strong&gt;5 had critical findings.&lt;/strong&gt; The most interesting: an invisible character right before a bash block in an agent spec. Coincidence or intention? That's exactly what the tool is for. Every finding was byte-verified manually and is public: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md" rel="noopener noreferrer"&gt;real-world findings&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Double dogfooding
&lt;/h2&gt;

&lt;p&gt;Two things happened that I could not have staged better:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;(a)&lt;/strong&gt; GitHub's own push protection blocked one of my pushes — a &lt;strong&gt;fake token in my own test file&lt;/strong&gt; triggered &lt;code&gt;GH013: Push cannot contain secrets&lt;/code&gt;. The biggest code host on the internet demonstrated on &lt;em&gt;my&lt;/em&gt; repo exactly what AgentGuard catches on &lt;em&gt;yours&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;(b)&lt;/strong&gt; Weeks later, after we shipped the v0.2.1 bypass protection, &lt;strong&gt;our own gate blocked our own pull request&lt;/strong&gt; during the self-test — the new rule ignores any &lt;code&gt;.agentguard-ignore&lt;/code&gt; shipped inside a PR, and our self-test workflow had relied on the old behavior. Red check. Merge refused. Working as designed. The full story is in the &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/CHANGELOG.md" rel="noopener noreferrer"&gt;changelog&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Yesterday my own security tool blocked my own pull request. That is the best demo a security product can have.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. What shipped in v0.2.1
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fail-closed gates:&lt;/strong&gt; a typo in &lt;code&gt;exit-on&lt;/code&gt; no longer silently disables the gate — it fails loudly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PR bypass protection:&lt;/strong&gt; a &lt;code&gt;.agentguard-ignore&lt;/code&gt; shipped inside a PR is ignored; exclusions come only from the trusted workflow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hardened Pro server:&lt;/strong&gt; HMAC length checks, 1 MB webhook body limit, per-repo installation resolution, safe tarball extraction (size limit, symlink/traversal rejection).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;New secret patterns:&lt;/strong&gt; private keys, GitHub PATs, npm, Stripe, Slack webhooks. Details in &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/SECURITY.md" rel="noopener noreferrer"&gt;SECURITY.md&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  5. The bot blocked an attack, live
&lt;/h2&gt;

&lt;p&gt;The GitHub App comments on every PR with a grade and findings, and sets a check-run gate. The proof is a real pull request: a planted attack got &lt;strong&gt;Note E, a red check, and no merge&lt;/strong&gt; — &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;see it live&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. The landing page now shows the moment
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;landing page&lt;/a&gt; has a live scan terminal in the hero: it types through files, finds the planted instruction, and ends on the green &lt;strong&gt;MERGE BLOCKED&lt;/strong&gt; moment — the exact emotion this product sells: &lt;em&gt;your agent reads your repo; your gate reads with it.&lt;/em&gt; Measured quality, not decoration: Lighthouse 100/100/100/100 on desktop and mobile, LCP 179 ms, CLS ~0, no horizontal scroll down to 320 px.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;MIT-licensed, free for public repos on the GitHub Marketplace. Reply with your repo and get a free first scan — or open a request directly: &lt;a href="https://github.com/agentguard-dev/agentguard/issues/new?template=audit-request.yml&amp;amp;labels=audit-request" rel="noopener noreferrer"&gt;audit/trial/redteam form&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;🔗 Code: &lt;a href="https://github.com/agentguard-dev/agentguard" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard&lt;/a&gt;&lt;br&gt;
🛒 Marketplace: &lt;a href="https://github.com/marketplace/actions/agentguard-security" rel="noopener noreferrer"&gt;https://github.com/marketplace/actions/agentguard-security&lt;/a&gt;&lt;br&gt;
📊 Verified findings: &lt;a href="https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard/blob/main/docs/REAL-WORLD-FINDINGS.md&lt;/a&gt;&lt;br&gt;
🔴 Live demo (attack blocked): &lt;a href="https://github.com/agentguard-dev/agentguard-demo/pull/2" rel="noopener noreferrer"&gt;https://github.com/agentguard-dev/agentguard-demo/pull/2&lt;/a&gt;&lt;br&gt;
🌐 Landing page: &lt;a href="https://agentguard-dev.github.io/agentguard/" rel="noopener noreferrer"&gt;https://agentguard-dev.github.io/agentguard/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>opensource</category>
      <category>agents</category>
    </item>
  </channel>
</rss>
