Topic · 3 posts
AI agents
Every Inline Code post tagged AI agents, ordered most recent first.
AI · Channel security
OpenClaw, WhatsApp and Telegram: the phone-linked AI agent threat model, the attacks already in the wild, and the gold-standard alternatives
OpenClaw lets anyone wire a personal WhatsApp or Telegram account to an AI agent in ten minutes. Bitsight found 30,000 instances exposed on the public internet in a fortnight. This is the architecture, the attacks, the config that breaks it, and the official-API pattern that holds.
AI · Architecture
Long-term memory for agnostic agents: a working architecture on Bedrock AgentCore
Bedrock AgentCore gives you a managed runtime, a long-term memory store, and a deliberately framework- and model-agnostic SDK — which means the agent code stays portable while the memory plane becomes the new audit liability. Here is the architecture that uses AgentCore Memory properly, the governance controls memory-poisoning and Privacy Act obligations force on top of it, and the rollout cadence that keeps the deployment defensible.
AI · Authorisation
OAuth scopes weren't built for AI agents: the delegation model that holds up under prompt injection
OAuth scopes assume a human approves once, an app does narrow work, and the trust horizon is months. AI agents break every part of that assumption. The architecture that holds is a two-principal model with short-lived delegation tokens, ReBAC for structure, ABAC for context, and per-action consent gating destructive operations. Here is the design and the rollout.
Browse other topics
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.