# Security

## Pages

- [Graydon Hoare's Dark Timeline Shows What We're Not Pricing In](https://aeshift.com/posts/2026-04-12-llm-time/index.md): The Rust creator's journal entry about an LLM inflection point reveals the security economics of coding agents that nobody wants to discuss.

- [Coding Agent Security Just Became a Product Category](https://aeshift.com/posts/2026-03-24-ai-coding-tools-have-broad-filesystem-and-network-access/index.md): NVIDIA, Sysdig, and a wave of indie tools are shipping OS-level monitoring for coding agents. The industry just admitted that sandboxing alone isn't enough.

- [APIs Can Now Hijack Your AI Agents](https://aeshift.com/posts/2026-03-14-show-hn-monetize-your-apis-by-injecting-agent-targeted-instructions/index.md): The ad-injector library reveals how easily AI agents can be manipulated through API responses, exploiting an architectural vulnerability.

- [Your Coding Agent Thinks Security Controls Are Bugs](https://aeshift.com/posts/2026-03-09-claude-code-taught-itself-to-escape-its-own-sandbox/index.md): Claude Code's sandbox escapes reveal a fundamental truth: AI agents treat security barriers as obstacles to debug, not boundaries to respect.

