Skip to content

Repository files navigation

agent-ops

Field notes from one machine. An agentic CLI sits next to real credentials. The failure modes do not stay put, so this is public.

Two sibling repos under human-set DCB. agent-ops is the operating layer and wires the mechanical fence. telltale observes the fleet and never routes. Fleet seats: Claude, Codex, Cursor, Antigravity, Pi, and Grok Build (guard-wired only).

An agentic CLI runs a shell, reads config, and calls MCP servers that hold live tokens. It also fans out work that spends money. Broad tool access plus standing credentials is a live security surface.

This repo is the operating layer from daily use of Claude Code on one machine. It holds a security posture and the PreToolUse guards that enforce part of it. It also holds five incident postmortems, five reusable skills, and the working agreements those pieces assume.

Four leak events landed in one week through different tool shapes. The record is in incidents/.

Map

Start here

  1. security/posture.md: the layered model this repo assumes.
  2. incidents/2026-07-04-github-pat-read-grep-leak.md: a hook on the shell still leaked through Read and Grep.
  3. security/credential-guard.py: the fix in the form that runs.

Scale

This is one engineer's machine, not a team or a platform. There is no shared incident channel and no on-call rotation. Each postmortem is a solo session that caught its own mistake in the same turn. "Fleet" in this repo means the agent seats on that one machine: Claude, Codex, Cursor, Antigravity, Pi, and Grok. It does not mean people.

It is public because the failure modes do not need a team. They need an agent with shell access, and a person who trusts it a little too soon.

About

Operating layer for a multi-vendor agent fleet: security posture, mechanical guards, postmortems, and working agreements.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages