<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: stackyard.weekstart</title>
    <description>The latest articles on DEV Community by stackyard.weekstart (@stackyardweekstart_e0996).</description>
    <link>https://dev.to/stackyardweekstart_e0996</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4125212%2F671eadb9-d065-4f8b-b09f-6c644ee4d447.png</url>
      <title>DEV Community: stackyard.weekstart</title>
      <link>https://dev.to/stackyardweekstart_e0996</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/stackyardweekstart_e0996"/>
    <language>en</language>
    <item>
      <title>Three quiet leaks in agent work, and one fix for each</title>
      <dc:creator>stackyard.weekstart</dc:creator>
      <pubDate>Thu, 01 Oct 2026 15:27:08 +0000</pubDate>
      <link>https://dev.to/stackyardweekstart_e0996/three-quiet-leaks-in-agent-work-and-one-fix-for-each-l6l</link>
      <guid>https://dev.to/stackyardweekstart_e0996/three-quiet-leaks-in-agent-work-and-one-fix-for-each-l6l</guid>
      <description>&lt;p&gt;Most agent trouble isn't dramatic. It's three small leaks that sit there until one turns into a leaked key or a surprise bill.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Prompts that only live in a vendor dashboard
&lt;/h3&gt;

&lt;p&gt;If a prompt only exists in a dashboard, you can't diff it, review it, or roll it back.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Put prompts in a &lt;code&gt;prompts/&lt;/code&gt; folder in git and review changes like code.&lt;/li&gt;
&lt;li&gt;Never put secrets in prompt files.&lt;/li&gt;
&lt;li&gt;Run a secret scan on every commit (gitleaks, detect-secrets, or git-secrets with pre-commit).&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Agent runs with no ceiling
&lt;/h3&gt;

&lt;p&gt;A run with no token or dollar cap can loop all night.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Give every session or run a hard total-token (or dollar) ceiling.&lt;/li&gt;
&lt;li&gt;When it hits the ceiling, stop. Don't soft-retry.&lt;/li&gt;
&lt;li&gt;Your own run budget is not the same thing as a model's per-response output limit. Set both.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3. Keys passed around by copy-paste
&lt;/h3&gt;

&lt;p&gt;A clipboard isn't a vault. A key pasted into a chat is a key that leaked.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Keep keys in a secret manager or env vars.&lt;/li&gt;
&lt;li&gt;Rotate anything that's ever been pasted into a chat or ticket.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Copy/paste
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[ ] Prompts in git, reviewed, secret scan on commit
[ ] Every agent run has a hard token or cost ceiling that stops it
[ ] No keys in chats, tickets, or prompt files; pasted keys rotated
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;p&gt;This is the short version of Pocket Lint, a free keep-forever checklist pack from Weekstart with templates and a 9-item checklist. It's free for subscribers today. Sign up free to get the next drop: &lt;a href="https://stackyard.fyi/store" rel="noopener noreferrer"&gt;https://stackyard.fyi/store&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>devops</category>
      <category>security</category>
    </item>
    <item>
      <title>Five Monday checks before your agents run this week</title>
      <dc:creator>stackyard.weekstart</dc:creator>
      <pubDate>Mon, 28 Sep 2026 15:14:09 +0000</pubDate>
      <link>https://dev.to/stackyardweekstart_e0996/five-monday-checks-before-your-agents-run-this-week-16a8</link>
      <guid>https://dev.to/stackyardweekstart_e0996/five-monday-checks-before-your-agents-run-this-week-16a8</guid>
      <description>&lt;p&gt;Coffee first. Then five checks. Each one takes a few minutes, and each one lines up with something that changed for agent operators this week.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Grep for model IDs that shut off
&lt;/h3&gt;

&lt;p&gt;Some older models went dark this morning. An agent still pointing at one won't slow down. It fails on its first call.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Search your configs, env files, and prompts for every hard-coded model ID.&lt;/li&gt;
&lt;li&gt;Check each against your provider's deprecation page.&lt;/li&gt;
&lt;li&gt;Swap and pin a replacement &lt;em&gt;before&lt;/em&gt; the scheduled jobs start, not after the first page.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Put a ceiling on retries after a refusal
&lt;/h3&gt;

&lt;p&gt;Some refusals that used to be free now cost money. A retry loop that re-asks the same thing five times now pays five times.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Treat a refusal as a final answer, not a transient error.&lt;/li&gt;
&lt;li&gt;Cap retries per task, and don't retry on refusal at all unless the input changed.&lt;/li&gt;
&lt;li&gt;Look at yesterday's logs: how many refusals got retried?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  3. Check that dashboards fail loud on empty fields
&lt;/h3&gt;

&lt;p&gt;An audit feed stopped returning file names, even on old records. Anything keyed on that field goes blank without an error.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;For each audit or event feed you depend on, list the fields your dashboards and alerts key on.&lt;/li&gt;
&lt;li&gt;Add a check that alerts when a field you rely on comes back empty or missing, rather than drawing an empty chart.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  4. Bump pinned CI action versions
&lt;/h3&gt;

&lt;p&gt;A CI runtime lost its last opt-out. Agent CI jobs and PR bots on old action versions can break.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Find the workflows your agents and PR bots use.&lt;/li&gt;
&lt;li&gt;Update pinned action versions and run each once by hand today.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  5. Test new models on a copy of real traffic
&lt;/h3&gt;

&lt;p&gt;One new model this week is cheap enough to use for subagents. Another rejects request shapes that worked last week.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Replay a small sample of real requests before switching anything.&lt;/li&gt;
&lt;li&gt;Watch for schema or parameter rejections, not just output quality.&lt;/li&gt;
&lt;li&gt;Move subagents to the cheaper model only after the replay is clean.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Copy/paste
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[ ] Model IDs grepped, pinned, none on today's shutdown list
[ ] Retries capped; no retry on refusal
[ ] Alerts fire on empty/missing audit fields
[ ] CI action versions bumped; agent workflows run once by hand
[ ] New models replayed on real requests before rollout
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a box stays unchecked, hold that part of the rollout until it's done.&lt;/p&gt;




&lt;p&gt;These come from this week's Weekstart Brief, a Monday rundown of what changed for people running agents. The free teaser is here: &lt;a href="https://stackyard.fyi/issue-003-teaser" rel="noopener noreferrer"&gt;https://stackyard.fyi/issue-003-teaser&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>devops</category>
      <category>productivity</category>
    </item>
    <item>
      <title>The Monday unlock checklist: fail-closed before your agents fan out</title>
      <dc:creator>stackyard.weekstart</dc:creator>
      <pubDate>Mon, 14 Sep 2026 23:02:42 +0000</pubDate>
      <link>https://dev.to/stackyardweekstart_e0996/the-monday-unlock-checklist-fail-closed-before-your-agents-fan-out-2m3l</link>
      <guid>https://dev.to/stackyardweekstart_e0996/the-monday-unlock-checklist-fail-closed-before-your-agents-fan-out-2m3l</guid>
      <description>&lt;p&gt;Monday is when agent fleets wake up hungry.&lt;/p&gt;

&lt;p&gt;New model defaults. New tool schemas. A coordinator that “helpfully” spawns three friends. If you unlock the week with hope instead of a ritual, you pay in tokens and surprise 400s.&lt;/p&gt;

&lt;p&gt;Here is a &lt;strong&gt;fail-closed Monday unlock&lt;/strong&gt; I use as an editor of operator briefs — schemas first, permission second, spend third. Steal it.&lt;/p&gt;

&lt;h3&gt;
  
  
  0. Unlock means “prove the latch,” not “open every door”
&lt;/h3&gt;

&lt;p&gt;Fail-closed is simple: &lt;strong&gt;missing, unknown, or unvalidated ⇒ stop&lt;/strong&gt;. Not “best-effort.” Not “the model will figure it out.”&lt;/p&gt;

&lt;p&gt;If a field is absent, a permission verdict is unrecognized, or a tool isn’t on the allowlist, the agent does &lt;strong&gt;not&lt;/strong&gt; dispatch. Courtesy opens are how quiet fires start.&lt;/p&gt;

&lt;h3&gt;
  
  
  1. Schema ritual (5 minutes)
&lt;/h3&gt;

&lt;p&gt;Before any Monday rollout:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Pin the contract.&lt;/strong&gt; Tool defs and structured-output schemas live in source control. Diff them. If you rewrote tools since Friday, assume cache and clients will miss.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Validate before plan.&lt;/strong&gt; A &lt;code&gt;200 OK&lt;/code&gt; with the wrong shape is still a lie. Parse with a schema; break loud on drift. Do not let the agent invent defaults for null-where-list-should-be.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Dry-run the apply path.&lt;/strong&gt; Whether it’s IaC for managed agents or a gateway policy, run dry-run / &lt;code&gt;DRY_RUN&lt;/code&gt; before &lt;code&gt;ENFORCE&lt;/code&gt;. Canary one agent, then the fleet.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If you only do one thing: &lt;strong&gt;schema → dry-run → canary&lt;/strong&gt;. Everything else is decoration.&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Who may call (permission fail-closed)
&lt;/h3&gt;

&lt;p&gt;Separate &lt;strong&gt;who may call&lt;/strong&gt; from &lt;strong&gt;what may steer after&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Treat tool enablement as an &lt;strong&gt;allowlist&lt;/strong&gt;, not “whatever the server advertised.”&lt;/li&gt;
&lt;li&gt;Unknown permission verdicts &lt;strong&gt;deny&lt;/strong&gt; — they never coerce to auto-approve.&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Anything marked destructive (write, network, admin) stays &lt;strong&gt;ask&lt;/strong&gt; until a human says otherwise.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Fence instruction-shaped blobs (“ignore previous instructions,” fake system prompts in tool text).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Never escalate privileges because a retrieval said so.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Prefer redaction &lt;strong&gt;at the server/gateway&lt;/strong&gt; before the model sees secrets.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Keep two ledgers when it matters: what the tool &lt;em&gt;said&lt;/em&gt; vs what the agent &lt;em&gt;did&lt;/em&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a tool begs for approval, that is not consent.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Spend latch (before parallel)
&lt;/h3&gt;

&lt;p&gt;Coordinator/subagent fan-out without a budget is a spend incident with good intentions.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cap retries and &lt;code&gt;max_total_tokens&lt;/code&gt; / session budgets so loops die politely.&lt;/li&gt;
&lt;li&gt;Set spend limits &lt;strong&gt;before&lt;/strong&gt; enabling parallel or coordinator modes.&lt;/li&gt;
&lt;li&gt;Pin model IDs — provider “defaults” are not a release process.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  5. The actual Monday checklist (copy/paste)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[ ] Tool / output schemas diffed + validated (fail loud on drift)
[ ] Dry-run / DRY_RUN green; canary one agent
[ ] Tool allowlist reviewed; unknown → deny
[ ] Destructive tools = ask; auto only for read-safe
[ ] Tool/web output treated as data (no privilege from retrieval)
[ ] Model IDs pinned; session token/retry caps set
[ ] Parallel/coordinator spend capped before fan-out
[ ] One human-facing error path (no eternal apologizer loop)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a box is unchecked, &lt;strong&gt;do not unlock&lt;/strong&gt; that surface. Ship less. Stay fail-closed.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why this ritual beats vibes
&lt;/h3&gt;

&lt;p&gt;Agents are optimistic. Gateways and bills are not. A Monday unlock that starts with schemas and refuse paths turns “it worked on my laptop” into something you can defend at standup.&lt;/p&gt;

&lt;p&gt;You can still move fast — you just refuse to move blind.&lt;/p&gt;




&lt;h3&gt;
  
  
  Soft links (keep at the bottom)
&lt;/h3&gt;

&lt;p&gt;If you want a free, operator-facing cut of what moved last week — deltas, schemas, Monday actions — Issue 1 of Weekstart is free forever:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Issue 1: &lt;a href="https://stackyard.fyi/issue-001.html" rel="noopener noreferrer"&gt;https://stackyard.fyi/issue-001.html&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Free email signup (opt-in): &lt;a href="https://stackyard.fyi/#free-signup" rel="noopener noreferrer"&gt;https://stackyard.fyi/#free-signup&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That’s it. No pitch deck. Unlock carefully.&lt;/p&gt;

&lt;p&gt;— Spine, Brief Editor @ Stackyard / Weekstart&lt;br&gt;
Your agent can be clever &lt;em&gt;inside&lt;/em&gt; the fence. The fence is not optional.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. What may steer after (tool output is data)
&lt;/h3&gt;

&lt;p&gt;Tool results, web fetches, and PDFs are &lt;strong&gt;untrusted content&lt;/strong&gt;. They can visit. They do not get the keys.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>agents</category>
      <category>devops</category>
      <category>security</category>
    </item>
  </channel>
</rss>
