<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Makan</title>
    <description>The latest articles on DEV Community by Makan (@makan09).</description>
    <link>https://dev.to/makan09</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4166534%2F816e6f6d-664c-4874-b575-7aeac43f1d5f.jpg</url>
      <title>DEV Community: Makan</title>
      <link>https://dev.to/makan09</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/makan09"/>
    <language>en</language>
    <item>
      <title>Why Your AI Agent Shouldn't Hold API Keys (And How We Fixed Human-in-the-Loop Fatigue)</title>
      <dc:creator>Makan</dc:creator>
      <pubDate>Tue, 06 Oct 2026 13:33:48 +0000</pubDate>
      <link>https://dev.to/makan09/why-your-ai-agent-shouldnt-hold-api-keys-and-how-we-fixed-human-in-the-loop-fatigue-4odd</link>
      <guid>https://dev.to/makan09/why-your-ai-agent-shouldnt-hold-api-keys-and-how-we-fixed-human-in-the-loop-fatigue-4odd</guid>
      <description>&lt;p&gt;Deploying autonomous AI agents into production currently forces developers into a dangerous trade-off:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The Security Nightmare:&lt;/strong&gt; You give your agent broad API keys (AWS, Stripe, Database, SMTP). If the agent suffers a prompt injection or hallucinates, those keys are exposed in memory or used in unintended ways.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The Automation Killer:&lt;/strong&gt; You try to fix security by enforcing a rigid "Human-In-The-Loop" (HITL) prompt for &lt;em&gt;every single action&lt;/em&gt;. Soon, your team suffers from alert fatigue, and the agent loses its main value: automation.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;We built &lt;strong&gt;&lt;a href="https://github.com/Pryxor/pryxor" rel="noopener noreferrer"&gt;Pryxor&lt;/a&gt;&lt;/strong&gt; (Apache 2.0 open-source) to eliminate this false choice using two core architecture principles.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. Absolute Credential Isolation: The Agent Holds Zero Keys
&lt;/h2&gt;

&lt;p&gt;Traditional guardrails inspect prompts or outputs &lt;em&gt;next to&lt;/em&gt; the agent, but the agent process still holds the live environment tokens. &lt;/p&gt;

&lt;p&gt;Pryxor sits &lt;em&gt;between&lt;/em&gt; the agent and your systems as a &lt;strong&gt;Zero Trust Gateway&lt;/strong&gt;.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Traditional Setup:
[Agent Process (Holds API Keys)] ---&amp;gt; [Prompt Guardrail] ---&amp;gt; [Production Systems]
*(If prompt injection succeeds, keys in memory are compromised)*

Pryxor Architecture:
[Agent Process (Holds ZERO Keys)] ---&amp;gt; [Pryxor Gateway] ---&amp;gt; [Production Systems]
*(Agent emits intention only. Keys live exclusively inside Pryxor)*
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Why this matters:&lt;/strong&gt;&lt;br&gt;
Even if an attacker completely compromises the model through a complex multi-stage prompt injection, &lt;strong&gt;there are no credentials to steal&lt;/strong&gt;. The agent never sees the API key, database password, or bearer token. It can only emit an &lt;em&gt;intent&lt;/em&gt; to call a tool.&lt;/p&gt;


&lt;h2&gt;
  
  
  2. Optimized Human-in-the-Loop: Review by Exception Only
&lt;/h2&gt;

&lt;p&gt;Forcing a human to approve every minor tool call makes autonomous agents useless. &lt;/p&gt;

&lt;p&gt;Pryxor solves alert fatigue through a &lt;strong&gt;three-gate evaluation engine&lt;/strong&gt; with an explicit &lt;code&gt;HOLD&lt;/code&gt; state:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Gate&lt;/th&gt;
&lt;th&gt;Status&lt;/th&gt;
&lt;th&gt;Execution Behavior&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;✅&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;APPROVED&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Safe, within-policy calls execute automatically using Pryxor's isolated keys.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;⏸&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;HOLD&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Sensitive or out-of-bound calls are quarantined. &lt;strong&gt;No system is touched&lt;/strong&gt; until approved.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;⛔&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;BLOCKED&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Malicious or unauthorized calls are dropped immediately.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Instead of babysitting every call, your team only intervenes when an action triggers a specific risk rule (e.g., emailing an external domain, mutating production data, or exceeding a rate threshold).&lt;/p&gt;


&lt;h2&gt;
  
  
  How it Works in Practice
&lt;/h2&gt;
&lt;h3&gt;
  
  
  Step 1: The Agent Emits an Intention
&lt;/h3&gt;

&lt;p&gt;The agent attempts to send an email to an external address. It calls the tool payload without needing an SMTP key:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"tool_name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"send_email"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"parameters"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"to"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"external_client@partner.com"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="nl"&gt;"subject"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Invoice Details"&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Step 2: Policy Evaluation (The Exception Rule)
&lt;/h3&gt;

&lt;p&gt;Pryxor evaluates the call against a simple, human-readable JSON policy (&lt;code&gt;configs/sectors/email.json&lt;/code&gt;):&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"type"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"declarative"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"rules"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"auto-approve-internal"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"when"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"tool"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"send_email"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"to_domain_in"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"mycompany.com"&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"then"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"approve"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"name"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"hold-external-recipients"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"when"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;"tool"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"send_email"&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"then"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"hold"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"EXTERNAL_EMAIL_REQUIRES_APPROVAL"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"message"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"External recipient detected. Human review required."&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Internal emails (&lt;code&gt;@mycompany.com&lt;/code&gt;):&lt;/strong&gt; Executed automatically (&lt;code&gt;APPROVED&lt;/code&gt;). Zero human friction.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;External emails:&lt;/strong&gt; Quarantined instantly (&lt;code&gt;HOLD&lt;/code&gt;). The external server is &lt;strong&gt;never contacted&lt;/strong&gt;, and the agent receives a &lt;code&gt;HOLD&lt;/code&gt; status, ending its turn gracefully.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Step 3: Out-of-Band Human Sign-Off
&lt;/h3&gt;

&lt;p&gt;An operator reviews the quarantined action in the terminal or CLI and approves it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nv"&gt;$ &lt;/span&gt;python pryxor_cli.py actions approve hold_a4bdeee3
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only after human approval does Pryxor execute the real API call using credentials the agent never saw or held.&lt;/p&gt;




&lt;h2&gt;
  
  
  Zero-Code Integration
&lt;/h2&gt;

&lt;p&gt;Pryxor integrates with your existing stack without requiring you to rewrite your agent logic:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Model Context Protocol (MCP):&lt;/strong&gt; Connects natively to Claude Desktop, Cursor, and Zed out of the box.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Framework Adapters:&lt;/strong&gt; Swap out standard tool definitions in &lt;strong&gt;LangChain&lt;/strong&gt;, &lt;strong&gt;CrewAI&lt;/strong&gt;, or &lt;strong&gt;OpenAI Agents SDK&lt;/strong&gt; with &lt;code&gt;PryxorTool&lt;/code&gt;.
&lt;/li&gt;
&lt;/ul&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="n"&gt;pryxor&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;PryxorTool&lt;/span&gt;

&lt;span class="c1"&gt;# Replace direct API tools with Zero-Trust Pryxor proxies
&lt;/span&gt;&lt;span class="n"&gt;email_tool&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;PryxorTool&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;send_email&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;runtime_url&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;http://localhost:8080&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  We Need Your Honest Feedback
&lt;/h2&gt;

&lt;p&gt;Pryxor is early-stage open source (Apache 2.0). The core engine runs as a lightweight Docker container with a single SQLite state file.&lt;/p&gt;

&lt;p&gt;We built this because we believe agentic AI cannot reach real enterprise production without zero-trust execution boundaries.&lt;/p&gt;

&lt;p&gt;We want you to tear this architecture apart:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Is credential isolation at the proxy level enough for your production setup?&lt;/li&gt;
&lt;li&gt;What edge cases would break this exception-based &lt;code&gt;HOLD&lt;/code&gt; model in your pipeline?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;📂 &lt;strong&gt;GitHub Repository:&lt;/strong&gt; &lt;a href="https://github.com/Pryxor/pryxor" rel="noopener noreferrer"&gt;github.com/Pryxor/pryxor&lt;/a&gt;&lt;br&gt;&lt;br&gt;
⚡ &lt;strong&gt;Quickstart:&lt;/strong&gt; &lt;a href="https://github.com/Pryxor/pryxor/blob/main/QUICKSTART.md" rel="noopener noreferrer"&gt;QUICKSTART.md&lt;/a&gt; (Run an end-to-end &lt;code&gt;HOLD&lt;/code&gt; walkthrough in 5 minutes)&lt;/p&gt;

&lt;p&gt;Drop your thoughts, critiques, or feature requests in the comments below!&lt;/p&gt;

</description>
      <category>ai</category>
      <category>python</category>
      <category>opensource</category>
      <category>security</category>
    </item>
  </channel>
</rss>
