Notes from the kennel.
Engineering deep-dives, releases, and what we learn watching agents misbehave.
Anatomy of a blocked command
What actually happens in the 0.8 milliseconds between an agent deciding to destroy your infrastructure and OpenLeash saying no.
OpenLeash 0.35: the policy engine rewrite
4× faster evaluation, streaming policy reloads, and a new dry-run mode for testing rules before they bite.
How prompt injection actually reaches your coding agent
READMEs, issue comments, and skill files — the three doors injections walk through, with real samples we caught.
token-saver hit 50k installs — here's what it trims
The plugin's author on duplicate file dumps, stale tool output, and why agents re-read the same file eleven times.
Self-hosting OpenLeash with Docker in 10 minutes
One compose file, your own Postgres, zero telemetry. The complete walkthrough, air-gapped setups included.
What CISOs ask us about agent guardrails
The eight questions that come up in every security review, and the honest answers — including the ones we don't love.
Ship a plugin in an afternoon: the write-up
From empty folder to the registry in four hours — a first-time author's honest log, mistakes included.