<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Arunima Chaudhuri</title>
    <description>The latest articles on DEV Community by Arunima Chaudhuri (@tinniaru3005).</description>
    <link>https://dev.to/tinniaru3005</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F946278%2F926ff73c-f99d-460b-9b65-b59ea148eee1.jpeg</url>
      <title>DEV Community: Arunima Chaudhuri</title>
      <link>https://dev.to/tinniaru3005</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tinniaru3005"/>
    <language>en</language>
    <item>
      <title>I Built an Open-Source Tool to Catch AI Agents Going Rogue</title>
      <dc:creator>Arunima Chaudhuri</dc:creator>
      <pubDate>Thu, 08 Oct 2026 17:35:57 +0000</pubDate>
      <link>https://dev.to/tinniaru3005/i-built-an-open-source-tool-to-catch-ai-agents-going-rogue-3fga</link>
      <guid>https://dev.to/tinniaru3005/i-built-an-open-source-tool-to-catch-ai-agents-going-rogue-3fga</guid>
      <description>&lt;p&gt;Everyone's building AI agents.&lt;/p&gt;

&lt;p&gt;But who's testing what happens when they go rogue?&lt;/p&gt;

&lt;p&gt;I built AgentSec: an open-source framework that tests prompt injection, tool misuse, secret leaks, MCP attacks &amp;amp; more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Built for developers. Open source.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;⭐ &lt;a href="https://github.com/invarislabs/invaris-agentsec" rel="noopener noreferrer"&gt;Explore on GitHub&lt;/a&gt;&lt;/p&gt;

</description>
      <category>opensource</category>
      <category>ai</category>
      <category>security</category>
      <category>showdev</category>
    </item>
    <item>
      <title>I Asked My Coding Agent a Yes-or-No Question. It Made a Commit.</title>
      <dc:creator>Arunima Chaudhuri</dc:creator>
      <pubDate>Thu, 08 Oct 2026 17:32:41 +0000</pubDate>
      <link>https://dev.to/tinniaru3005/i-asked-my-coding-agent-a-yes-or-no-question-it-made-a-commit-k1h</link>
      <guid>https://dev.to/tinniaru3005/i-asked-my-coding-agent-a-yes-or-no-question-it-made-a-commit-k1h</guid>
      <description>&lt;p&gt;I asked my AI coding agent a yes-or-no question.&lt;/p&gt;

&lt;p&gt;It made a commit instead.&lt;/p&gt;

&lt;p&gt;I never asked it to change anything.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When did "can do" become "authorized to do"?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This incident changed how I think about AI agent security.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://arunima-chaudhuri.hashnode.dev/i-asked-my-coding-agent-for-a-yes-or-no-it-made-a-commit" rel="noopener noreferrer"&gt;Here's what happened →&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>security</category>
      <category>productivity</category>
    </item>
    <item>
      <title>Building AI Agents? Here's What Can Go Wrong.</title>
      <dc:creator>Arunima Chaudhuri</dc:creator>
      <pubDate>Thu, 08 Oct 2026 17:30:57 +0000</pubDate>
      <link>https://dev.to/tinniaru3005/building-ai-agents-heres-what-can-go-wrong-1dj6</link>
      <guid>https://dev.to/tinniaru3005/building-ai-agents-heres-what-can-go-wrong-1dj6</guid>
      <description>&lt;p&gt;Your AI agent can execute code, access databases, and call APIs.&lt;/p&gt;

&lt;p&gt;But can it recognize malicious instructions?&lt;/p&gt;

&lt;p&gt;Prompt injection. Memory poisoning. Tool misuse. Secret leaks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Are you testing for any of these?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I wrote a beginner-to-pro guide:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://arunima-chaudhuri.hashnode.dev/agentsec-101-how-to-stop-your-ai-agent-from-going-rogue-a-beginner-to-pro-guide" rel="noopener noreferrer"&gt;AgentSec 101 →&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>beginners</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>The AI Agent Security Flaw That Doesn't Require Hacking</title>
      <dc:creator>Arunima Chaudhuri</dc:creator>
      <pubDate>Thu, 08 Oct 2026 17:28:26 +0000</pubDate>
      <link>https://dev.to/tinniaru3005/the-ai-agent-security-flaw-that-doesnt-require-hacking-1b6h</link>
      <guid>https://dev.to/tinniaru3005/the-ai-agent-security-flaw-that-doesnt-require-hacking-1b6h</guid>
      <description>&lt;p&gt;Imagine your AI agent reads a private file and emails it to someone.&lt;/p&gt;

&lt;p&gt;No hacked credentials. No forbidden tools.&lt;/p&gt;

&lt;p&gt;Every action was technically allowed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;But you never asked it to do that.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This is the security gap we're overlooking.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://arunima-chaudhuri.hashnode.dev/allowed-isn-t-authorized-testing-what-your-ai-agent-does-with-the-permissions-it-already-has" rel="noopener noreferrer"&gt;Read why →&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>agents</category>
      <category>programming</category>
    </item>
    <item>
      <title>Your AI Agent Passed Every Security Test. Should You Trust It?</title>
      <dc:creator>Arunima Chaudhuri</dc:creator>
      <pubDate>Thu, 08 Oct 2026 17:25:55 +0000</pubDate>
      <link>https://dev.to/tinniaru3005/your-ai-agent-passed-every-security-test-should-you-trust-it-5759</link>
      <guid>https://dev.to/tinniaru3005/your-ai-agent-passed-every-security-test-should-you-trust-it-5759</guid>
      <description>&lt;p&gt;Your AI agent passed every security test.&lt;/p&gt;

&lt;p&gt;100% pass rate. Zero findings. Green CI.&lt;/p&gt;

&lt;p&gt;But what if the test couldn't actually observe the dangerous behavior?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A passing test doesn't always prove safety.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Here's why that matters:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://arunima-chaudhuri.hashnode.dev/what-does-a-passing-agent-security-test-actually-prove" rel="noopener noreferrer"&gt;Read the full article →&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>testing</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
