security
This is the security tag archive on Will's Journal: every published post that shares this tag, listed in one place.
It is a collection page, not a topic essay — scan the cluster here instead of filtering the full journal index.
Which posts are tagged security?
AI Agents How do I stop an agent from doing something destructive
Stop destructive agent actions with a blast-radius table, an allowlisted tool set, and dual control on money and delete, enforced in code before the tool runs.
AI Agents Sandboxed Tool Use: Letting Agents Act Without Letting Them Loose
Tool use without a sandbox is an API key with opinions. Allowlists, scoped credentials, blast-radius caps, dry-runs, and human gates earn a production write.
Automation OAuth Tokens Will Expire: Stop Silent 401 Loops in Production
n8n refreshes OAuth on 401, not expires_in. Persist refresh tokens, set tokenExpiredStatusCode, pause on auth, and alert before quiet overnight 401 loops.
AI Agents Prompt Injection for Tool Agents: Stop Text from Becoming Actions
Stop prompt injection by isolating untrusted email and tickets from write tools, then gating every proposed call in code — never in the system prompt.
Automation Webhook Security for Automations: Signatures, Secrets, and Least Privilege
Verify Stripe and GitHub signatures on the raw body, reject replayed events, and allowlist vendor IPs before n8n runs CRM writes or payment side effects.
AI Agents Pre-Execution Policy Gates: The Kill Switch That Lives Outside the Prompt
Your agent’s kill switch is a pre-execution policy gate outside the prompt: allow, deny, or pending-approval before side effects — fail closed on outages.
What should you know about this tag archive?
What is this tag archive?
This is the security tag archive on Will's Journal: every published post that shares this tag, listed in one place.
Is this a guide to the topic, or a list of posts?
A list of posts. This page is a collection, not a topic essay — the 6 posts below are the security cluster on Will's Journal.