Open Source Credential Proxy and Vault for Agents

(twitter.com)

1 points | by vmatsiiako 7 hours ago ago

1 comments

  • Almured 7 hours ago

    Does this prevent a compromised agent from using the secret, or just seeing it? I’m thinking, if an agent gets hit with a prompt injection, could it still tell the vault to proxy a request that wipes a database for example, even if it never sees the actual API key?