
オカダリョウタロウ
40.2K posts

オカダリョウタロウ
@okdt
日本のセキュリティリサーチャ | アスタリスク・リサーチ代表📈 | 神戸デジタル・ラボCSA⚓️ | 神戸高専OB | BBT大学講師 | OWASP🐝Japan Leader | Hardening Project Organizer | SBOM CycloneDX | カレー🍛派|加速装置ほしい








I put together a practical and educational cheatsheet for hardening Claude Code (Anthropic’s CLI coding agent): github.com/okdt/claude-co… It covers sandbox isolation, deny/ask/allow permission rules, and custom hooks (PreToolUse) — mapped to LLM Top 10 categories (LLM01 Prompt Injection, LLM06 Excessive Agency, LLM09 Overreliance). Structured around principles we share here — least privilege, defense in depth, human-in-the-loop — applied to the specific context of an AI coding agent that executes shell commands and reads/writes files on your behalf. I started this as a personal draft, but I think the topic is broadly relevant. Would any existing project — AI Agent Security Cheat Sheet, LLM Top 10 supplementary materials, or something else — be a good home for this kind of content? Happy to adapt the format and contribute. Feedback welcome either way. Thanks @owasp @OWASP_AISVS @claudeai


【独自】オープンAI、動画生成アプリ「ソラ」を廃止へ on.wsj.com/3NCHXBY


サイバー対策製品「多すぎ」 大量アラートに担当者は疲弊、機能も重複 nikkei.com/article/DGXZQO…

