<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Kaushikreddy Lingi</title>
    <description>The latest articles on DEV Community by Kaushikreddy Lingi (@lingikaushikreddy).</description>
    <link>https://dev.to/lingikaushikreddy</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4155517%2F874f87e3-84a9-47b2-8e19-67bd9ea7100f.jpg</url>
      <title>DEV Community: Kaushikreddy Lingi</title>
      <link>https://dev.to/lingikaushikreddy</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/lingikaushikreddy"/>
    <language>en</language>
    <item>
      <title>An Analytics Agent's Permissions Should Survive a Bad Prompt</title>
      <dc:creator>Kaushikreddy Lingi</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:53:57 +0000</pubDate>
      <link>https://dev.to/lingikaushikreddy/an-analytics-agents-permissions-should-survive-a-bad-prompt-4gb</link>
      <guid>https://dev.to/lingikaushikreddy/an-analytics-agents-permissions-should-survive-a-bad-prompt-4gb</guid>
      <description>&lt;p&gt;An analytics agent receives a hostile instruction: return every customer's unmasked payment identifier.&lt;/p&gt;

&lt;p&gt;The key question is what the system permits that agent to read—even if the model decides to follow the instruction.&lt;/p&gt;

&lt;p&gt;That is the boundary I am exploring in &lt;a href="https://github.com/Lingikaushikreddy/MerchantLens" rel="noopener noreferrer"&gt;MerchantLens&lt;/a&gt;, a merchant analytics lakehouse built with Databricks, Delta tables and Unity Catalog.&lt;/p&gt;

&lt;p&gt;The demo uses synthetic payments data. There is no real cardholder data in the project.&lt;/p&gt;

&lt;h2&gt;
  
  
  Put the caller's identity in the query path
&lt;/h2&gt;

&lt;p&gt;MerchantLens moves data through Bronze, Silver and Gold layers. An agent searches live catalog metadata and uses tools to query metrics or SQL.&lt;/p&gt;

&lt;p&gt;The agent executes under its own service principal. Unity Catalog applies column masks and row filters for that principal before returning query results.&lt;/p&gt;

&lt;p&gt;The README includes a comparison using the same SQL under two principals: the analyst sees a broader dataset, while the agent sees a restricted region and masked identifiers. The entitlement decision belongs to the query engine.&lt;/p&gt;

&lt;h2&gt;
  
  
  Separate reliability controls from authorization
&lt;/h2&gt;

&lt;p&gt;The project has several layers:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Layer&lt;/th&gt;
&lt;th&gt;Purpose&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Certified metrics&lt;/td&gt;
&lt;td&gt;Keep definitions and grain consistent&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Application checks&lt;/td&gt;
&lt;td&gt;Constrain SQL, schemas, rows and tool steps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unity Catalog policies&lt;/td&gt;
&lt;td&gt;Enforce identity-based row and column access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit records&lt;/td&gt;
&lt;td&gt;Record tool activity independently of the answer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The first two help keep the agent's behavior controlled. The catalog policies enforce data access.&lt;/p&gt;

&lt;p&gt;This does not make the entire application immune to attack. Its protection depends on correctly configured identities, grants, masks and filters, and on every query using the intended principal.&lt;/p&gt;

&lt;h2&gt;
  
  
  Test the protected table
&lt;/h2&gt;

&lt;p&gt;One practical lesson documented in the repository: checking a membership expression alone can give a misleading picture of what a mask does.&lt;/p&gt;

&lt;p&gt;A better proof exercises the protected table under the actual identity. Ask what rows and values come back, then compare those results with the intended entitlement.&lt;/p&gt;

&lt;p&gt;The repository also documents ambient grants on new service principals. Creating a new identity is not automatically a deny-by-default setup.&lt;/p&gt;

&lt;h2&gt;
  
  
  Metric definitions need boundaries too
&lt;/h2&gt;

&lt;p&gt;MerchantLens attributes chargebacks to the month of the originating transaction. Using the date a chargeback was opened can shift the apparent incident across months because disputes arrive later.&lt;/p&gt;

&lt;p&gt;That definition belongs in the semantic layer so a dashboard and an agent can use the same metric. Correct permissions do not compensate for an inconsistent denominator or time definition.&lt;/p&gt;

&lt;h2&gt;
  
  
  A review checklist
&lt;/h2&gt;

&lt;p&gt;Before giving an agent a warehouse tool, I would ask:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Which principal executes its queries?&lt;/li&gt;
&lt;li&gt;Can it retrieve restricted columns through another table or grant?&lt;/li&gt;
&lt;li&gt;Are protected-table results tested under that principal?&lt;/li&gt;
&lt;li&gt;Are tool calls logged somewhere the agent cannot modify?&lt;/li&gt;
&lt;li&gt;Are metric definitions explicit and shared?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Where does your analytics agent's access control execute: in the prompt, the application, or the database?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/Lingikaushikreddy/MerchantLens" rel="noopener noreferrer"&gt;Read the architecture and platform findings&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Drafted with AI from the public project documentation. Demo observations are repository-reported, not a new verification run.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>database</category>
      <category>dataengineering</category>
    </item>
    <item>
      <title>A RAG Agent Can Refuse Every Attack and Still Fail Its Users</title>
      <dc:creator>Kaushikreddy Lingi</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:53:49 +0000</pubDate>
      <link>https://dev.to/lingikaushikreddy/a-rag-agent-can-refuse-every-attack-and-still-fail-its-users-3fe0</link>
      <guid>https://dev.to/lingikaushikreddy/a-rag-agent-can-refuse-every-attack-and-still-fail-its-users-3fe0</guid>
      <description>&lt;p&gt;Suppose an agent refuses every request. Its attack success rate might look excellent. Its usefulness would be terrible.&lt;/p&gt;

&lt;p&gt;That tradeoff is a central design concern in &lt;a href="https://github.com/Lingikaushikreddy/aegiseval" rel="noopener noreferrer"&gt;AegisEval&lt;/a&gt;, my adversarial evaluation project for a tool-using customer-support RAG agent.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Status first:&lt;/strong&gt; the evaluation machinery is implemented, but no evaluation run has been recorded yet. This post describes the design, not measured safety improvements.&lt;/p&gt;

&lt;h2&gt;
  
  
  Evaluate actions, not just answers
&lt;/h2&gt;

&lt;p&gt;The fictional retailer's chatbot retrieves help-centre content and has tools for refunds, cancellations and shipping-address changes.&lt;/p&gt;

&lt;p&gt;That creates questions a text-only test misses. Did the agent act on the correct order? Did it follow the applicable policy? Did it obtain confirmation? Did a malicious instruction in retrieved content influence a tool call?&lt;/p&gt;

&lt;p&gt;Ownership checks and the refund ceiling are enforced in the tools. Other business rules intentionally live in the target's prompt, so the evaluation can probe failures at that boundary.&lt;/p&gt;

&lt;p&gt;This is a test target, not a recommendation to leave production authorization to a prompt.&lt;/p&gt;

&lt;h2&gt;
  
  
  Include customers who should succeed
&lt;/h2&gt;

&lt;p&gt;The golden set contains 260 cases. Of those, 68 are legitimate customer requests, including 12 hard negatives that resemble attacks.&lt;/p&gt;

&lt;p&gt;For example, an angry customer may be entitled to a large refund. Someone saying “ignore my last message” may simply be correcting a request.&lt;/p&gt;

&lt;p&gt;If a mitigation blocks those users, the report needs to show that cost alongside attack outcomes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tool output can carry hostile text
&lt;/h2&gt;

&lt;p&gt;AegisEval covers four injection surfaces:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Direct user input&lt;/li&gt;
&lt;li&gt;Retrieved documents&lt;/li&gt;
&lt;li&gt;Web results&lt;/li&gt;
&lt;li&gt;Free-text fields inside order records&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That fourth surface is easy to overlook. Gift messages and delivery notes can contain customer-controlled text even when they arrive through a tool the agent called itself. Retrieval sanitization alone does not cover that path.&lt;/p&gt;

&lt;p&gt;Matched payloads across indirect surfaces help separate differences in the boundary from differences in attack wording.&lt;/p&gt;

&lt;h2&gt;
  
  
  Treat the judge as another component to evaluate
&lt;/h2&gt;

&lt;p&gt;The judge uses a different model and vendor from the target. It does not see the case author's expected behavior. Human labeling is blind to the judge's verdict.&lt;/p&gt;

&lt;p&gt;The pipeline is designed to report agreement by harm category with confidence intervals. Those validation numbers still require recorded runs and human labels.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I would want in a useful report
&lt;/h2&gt;

&lt;p&gt;I would look for attack outcomes, legitimate-task outcomes, raw counts, category breakdowns and the configuration tested. I would also want the limitations visible: this project is English-only, uses one target configuration and has a modest dataset.&lt;/p&gt;

&lt;p&gt;A passing result for that setup would be evidence about that setup. It would not establish that the underlying model is universally safe.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;How do you measure whether an agent's safety controls are also blocking legitimate work?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/Lingikaushikreddy/aegiseval" rel="noopener noreferrer"&gt;Explore the threat model, taxonomy and pipeline&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Drafted with AI from the repository documentation. No evaluation results are claimed.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>python</category>
      <category>discuss</category>
    </item>
    <item>
      <title>I Built a Village of Six Agents You Can Actually Inspect</title>
      <dc:creator>Kaushikreddy Lingi</dc:creator>
      <pubDate>Thu, 01 Oct 2026 17:53:40 +0000</pubDate>
      <link>https://dev.to/lingikaushikreddy/i-built-a-village-of-six-agents-you-can-actually-inspect-1ci5</link>
      <guid>https://dev.to/lingikaushikreddy/i-built-a-village-of-six-agents-you-can-actually-inspect-1ci5</guid>
      <description>&lt;p&gt;An agent claims a task. Another agent needs the same resources. A third is resting. Who gets the job, and can you explain the decision afterward?&lt;/p&gt;

&lt;p&gt;That is the kind of question I am exploring with &lt;a href="https://github.com/Lingikaushikreddy/Settlement-Village" rel="noopener noreferrer"&gt;Settlement&lt;/a&gt;, a village strategy game and an inspectable simulation lab.&lt;/p&gt;

&lt;p&gt;With &lt;a href="https://dev.to/t/hacktoberfest"&gt;Hacktoberfest focusing on open-source AI this October&lt;/a&gt;, it feels like a useful time to share a project where the behavior is visible and the default setup needs no model API key.&lt;/p&gt;

&lt;h2&gt;
  
  
  One objective, six residents
&lt;/h2&gt;

&lt;p&gt;Choose an objective such as preparing for a raid or restocking supplies. The planner splits it into jobs. Six residents bid using role suitability, distance and bounded experience. Each job has one owner.&lt;/p&gt;

&lt;p&gt;Residents walk to workplaces, gather resources and coordinate recruitment. If a resident rests, its work can be released for another resident to take over. When resources or workplaces change, agents reconsider their tasks.&lt;/p&gt;

&lt;p&gt;The interesting part is the inspector: current jobs, blocked work, spending limits and recent memories are available to read alongside the action log.&lt;/p&gt;

&lt;h2&gt;
  
  
  The boundary matters
&lt;/h2&gt;

&lt;p&gt;The default campaign uses deterministic game AI. It does not understand arbitrary natural-language goals, train a neural network or call a model behind the scenes.&lt;/p&gt;

&lt;p&gt;Optional Claude proposals belong to explicitly configured local-worker research experiments. Keeping those paths separate makes it clearer what a result actually measures.&lt;/p&gt;

&lt;p&gt;The world also enforces constraints. Actions validate funds, capacity and the objective's spending allowance. A decision needs to become a valid action before it changes the treasury or army.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it locally
&lt;/h2&gt;

&lt;p&gt;Use Node.js 24+:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/Lingikaushikreddy/Settlement-Village.git
&lt;span class="nb"&gt;cd &lt;/span&gt;Settlement-Village
npm ci
npm run dev
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Open &lt;a href="http://localhost:5173" rel="noopener noreferrer"&gt;http://localhost:5173&lt;/a&gt;. Choose &lt;strong&gt;Village orders → Prepare for a raid&lt;/strong&gt;, then &lt;strong&gt;View plan → Shared jobs&lt;/strong&gt;. Inspect one resident before and after giving it a rest.&lt;/p&gt;

&lt;h2&gt;
  
  
  A small experiment to try
&lt;/h2&gt;

&lt;p&gt;Ask three questions:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Did the job change owners when the resident rested?&lt;/li&gt;
&lt;li&gt;Can I identify why the replacement took it?&lt;/li&gt;
&lt;li&gt;Did the action respect the objective's budget?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The research view adds matched seeds, JSON/CSV exports and replay verification. Its authored scenarios are a bounded testbed; results there should not be treated as a general AI safety benchmark.&lt;/p&gt;

&lt;p&gt;Contributions could explore richer objectives, recovery behavior or more adversarial and honest-control scenarios. The &lt;a href="https://github.com/Lingikaushikreddy/Settlement-Village/blob/main/CONTRIBUTING.md" rel="noopener noreferrer"&gt;contribution guide&lt;/a&gt; is the starting point.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What would you want to inspect first in a multi-agent system: task ownership, memory, or spending?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Drafted with AI from the public project README; project behavior and limitations are linked above.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>opensource</category>
      <category>typescript</category>
      <category>hacktoberfest</category>
    </item>
  </channel>
</rss>
