DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Authentication vs Authorization (Like I'm 5 years Old)

Authentication vs Authorization (Like I'm 5 years Old)

2
Comments
3 min read
98% of MCP Tools Don't Tell AI Agents When to Use Them

98% of MCP Tools Don't Tell AI Agents When to Use Them

Comments
3 min read
Why Your CI/CD Pipeline Is Your Biggest Security Blind Spot (And How to Fix It)

Why Your CI/CD Pipeline Is Your Biggest Security Blind Spot (And How to Fix It)

Comments
6 min read
Why Pasting Client Data into ChatGPT is a GDPR Liability (and the Fix)

Why Pasting Client Data into ChatGPT is a GDPR Liability (and the Fix)

Comments
4 min read
The Right Way to Handle API Keys When Your Agent Reads Untrusted Content

The Right Way to Handle API Keys When Your Agent Reads Untrusted Content

3
Comments
4 min read
Compromised Litellm PyPI Packages (v1.82.7, v1.82.8) Expose Users to Security Risks: Mitigation Steps Available

Compromised Litellm PyPI Packages (v1.82.7, v1.82.8) Expose Users to Security Risks: Mitigation Steps Available

Comments
12 min read
How to Self-Host Vaultwarden with Docker

How to Self-Host Vaultwarden with Docker

1
Comments
7 min read
What CVE-2026-25253 Taught Me About Building Safe AI Assistants

What CVE-2026-25253 Taught Me About Building Safe AI Assistants

Comments
3 min read
This open-source tool scans uploads before they become a problem

This open-source tool scans uploads before they become a problem

Comments
3 min read
Frontend Security - What Your Browser Is Quietly Protecting You From

Frontend Security - What Your Browser Is Quietly Protecting You From

7
Comments 1
7 min read
Building Safer Email OTP Verification in Node.js: Expiry, Retries, and Lockouts

Building Safer Email OTP Verification in Node.js: Expiry, Retries, and Lockouts

Comments
5 min read
Separating Agent Tool Calls from Authorization and Evidence

Separating Agent Tool Calls from Authorization and Evidence

Comments 1
10 min read
I Scanned Random Lovable Projects for Security Flaws. Here's What I Found.

I Scanned Random Lovable Projects for Security Flaws. Here's What I Found.

Comments
2 min read
You probably haven't audited your MCP servers or AI agent skills. This tool does it for you.

You probably haven't audited your MCP servers or AI agent skills. This tool does it for you.

1
Comments 1
2 min read
ClawSec: Turn OpenClaw Into an Offensive Recon Assistant via Telegram

OpenClaw Challenge Submission 🦞

ClawSec: Turn OpenClaw Into an Offensive Recon Assistant via Telegram

4
Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.