<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Chanpreet Singh</title>
    <description>The latest articles on DEV Community by Chanpreet Singh (@chanpre75813933).</description>
    <link>https://dev.to/chanpre75813933</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4167511%2Fe1f0b143-cbe5-4971-8618-0d0c6ddf1fac.jpg</url>
      <title>DEV Community: Chanpreet Singh</title>
      <link>https://dev.to/chanpre75813933</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/chanpre75813933"/>
    <language>en</language>
    <item>
      <title>Your AI agent doesn't need fewer permissions. It needs a mission.</title>
      <dc:creator>Chanpreet Singh</dc:creator>
      <pubDate>Tue, 06 Oct 2026 23:46:45 +0000</pubDate>
      <link>https://dev.to/chanpre75813933/your-ai-agent-doesnt-need-fewer-permissions-it-needs-a-mission-3c6g</link>
      <guid>https://dev.to/chanpre75813933/your-ai-agent-doesnt-need-fewer-permissions-it-needs-a-mission-3c6g</guid>
      <description>&lt;p&gt;If you've been on dev Twitter or Hacker News this month, you've seen the stories. An agent asked to clean up a folder deletes tens of thousands of files. A coding agent launches hundreds of parallel runs nobody asked for and burns through a five-figure bill. Someone's OpenClaw setup emails their clients without approval. Someone else writes "never touch production" in CLAUDE.md, and the agent reads every secret in the &lt;code&gt;.env&lt;/code&gt; anyway.&lt;/p&gt;

&lt;p&gt;None of these agents were "hacked" in the movie sense. They were doing roughly what they were built to do: take actions with real tools. The problem is that nothing between the agent and the tool asked a simple question first:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is this action part of the job?&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Permissions aren't the same as intent
&lt;/h2&gt;

&lt;p&gt;The usual advice is to give agents fewer permissions. That helps, but it runs into a wall fast. A coding agent needs to delete files sometimes. An inbox agent needs to send email. A deploy agent needs to touch production. Take those away and the agent is useless; leave them and any one bad step can do damage.&lt;/p&gt;

&lt;p&gt;What's missing is a check on &lt;em&gt;intent&lt;/em&gt;, not just &lt;em&gt;access&lt;/em&gt;. "Delete files in &lt;code&gt;/tmp/build&lt;/code&gt;" during a cleanup task is fine. "Delete the home folder" during the same task is not. Both use the same permission.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'm building: Watchdog
&lt;/h2&gt;

&lt;p&gt;That's the idea behind Watchdog, one of the two things I'm building under &lt;a href="https://aloviaai.com" rel="noopener noreferrer"&gt;Alovia AI&lt;/a&gt;. You give your agent a one-line mission, like "triage my inbox and draft replies, never send." Before each action runs, Watchdog checks it against that mission. On-mission actions go through. Off-mission ones get stopped, and you see why.&lt;/p&gt;

&lt;p&gt;It sits around the agent's traffic rather than inside the model, so it works with any model, open-source or frontier, and with setups like Claude Code, Codex, OpenClaw or Hermes.&lt;/p&gt;

&lt;p&gt;I tested it against AgentDojo-style prompt-injection attacks, where a tool result tries to hijack the agent into doing something else. In our full configuration, &lt;strong&gt;0 of 809 attacks got through&lt;/strong&gt;. In a lighter policy-only mode, it stopped about half with &lt;strong&gt;zero false positives&lt;/strong&gt; on legitimate tasks.&lt;/p&gt;

&lt;h2&gt;
  
  
  The other side: Shield
&lt;/h2&gt;

&lt;p&gt;The same shift is hitting websites from the other direction. Site owners are posting about AI crawlers multiplying their Vercel bills, residential-proxy scrapers making up 99% of a small forum's traffic, and bots testing stolen cards through free trials.&lt;/p&gt;

&lt;p&gt;Shield sits in front of your site, alongside Cloudflare rather than replacing it, and stops abusive bots, AI scrapers and fake signups before they reach your origin, without putting a captcha in front of real people.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;It's in free private beta with 20 seats, for people running agents or sites that are getting hammered. If either of these sounds like your week, grab one at &lt;a href="https://aloviaai.com" rel="noopener noreferrer"&gt;aloviaai.com&lt;/a&gt; or drop a comment with what broke. I read every one.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Chan, building Alovia AI&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>agents</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
