Spurlock Studios
Contact
Tag

security

This is the security tag archive on Will's Journal: every published post that shares this tag, listed in one place.

It is a collection page, not a topic essay — scan the cluster here instead of filtering the full journal index.

Which posts are tagged security?

A violet ring. Thesis: STOP AGENT DOING SOMETHING DESTRUCTIVE. AI Agents

How do I stop an agent from doing something destructive

Stop destructive agent actions with a blast-radius table, an allowlisted tool set, and dual control on money and delete, enforced in code before the tool runs.

28 MIN
An expired brass key. Thesis: SANDBOXED TOOL USE LETTING AGENTS. AI Agents

Sandboxed Tool Use: Letting Agents Act Without Letting Them Loose

Tool use without a sandbox is an API key with opinions. Allowlists, scoped credentials, blast-radius caps, dry-runs, and human gates earn a production write.

23 MIN
Two clipped paper packets. Thesis: OAUTH TOKENS WILL EXPIRE STOP. Automation

OAuth Tokens Will Expire: Stop Silent 401 Loops in Production

n8n refreshes OAuth on 401, not expires_in. Persist refresh tokens, set tokenExpiredStatusCode, pause on auth, and alert before quiet overnight 401 loops.

20 MIN
A scuffed work smartphone with a blank glowing circular button. Thesis: PROMPT INJECTION TOOL AGENTS STOP. AI Agents

Prompt Injection for Tool Agents: Stop Text from Becoming Actions

Stop prompt injection by isolating untrusted email and tickets from write tools, then gating every proposed call in code — never in the system prompt.

18 MIN
A blank 21+ token. Thesis: WEBHOOK SECURITY AUTOMATIONS SIGNATURES SECRETS. Automation

Webhook Security for Automations: Signatures, Secrets, and Least Privilege

Verify Stripe and GitHub signatures on the raw body, reject replayed events, and allowlist vendor IPs before n8n runs CRM writes or payment side effects.

22 MIN
A cracked amber fuse. Thesis: PRE EXECUTION POLICY GATES KILL. AI Agents

Pre-Execution Policy Gates: The Kill Switch That Lives Outside the Prompt

Your agent’s kill switch is a pre-execution policy gate outside the prompt: allow, deny, or pending-approval before side effects — fail closed on outages.

16 MIN
FAQ

What should you know about this tag archive?

What is this tag archive?

This is the security tag archive on Will's Journal: every published post that shares this tag, listed in one place.

Is this a guide to the topic, or a list of posts?

A list of posts. This page is a collection, not a topic essay — the 6 posts below are the security cluster on Will's Journal.