Hacker News new | ask | show | jobs
by renezander030 1 day ago
On the egress judge: an LLM reviewing connector calls inline is a probabilistic control sitting where a capability grant belongs. The operations that actually cause damage are largely enumerable: writes, deletes, and bulk reads of personal data. Those should be absent from the scoped token rather than present and then argued about by a judge with a nonzero false-negative rate under adversarial input, with the judge kept for the ambiguous long tail where enumeration genuinely fails. This is the WAF story again, request inspection in front of an app was a useful compensating control, and every team that mistook it for the boundary relearned that the boundary was the parameterized query and the database grant.