Transcript
JOSH: It's Wednesday, July 8. This is Build or Be Replaced — powered by ScanBrief.dev. I'm Josh, here with Erik Anderson.
ERIK: Today is about agents, trust, and why your private repo should not be one clever prompt away from becoming public confetti.
JOSH: Stick around — Erik's got an AI pro tip at the end about building a dead-simple agent quarantine lane.
[pause]
JOSH: ScanBrief scored 86 items across 54 sources today. First headline: researchers tricked GitHub's AI agent into leaking private repos. Erik, that's bad, right?
ERIK: Bad and predictable. Any agent with repo access is now part developer, part intern, part attack surface. You don't give it broad permissions and hope vibes protect you.
JOSH: Next one: local, CPU-friendly, high-quality TTS with Kokoro.
ERIK: That matters. Local voice means faster loops, cheaper experiments, and less sensitive text leaving your machine. If you're building agents that talk, local TTS is plumbing, not a toy.
JOSH: Third headline: Tenda firmware has a hidden authentication backdoor.
ERIK: Router firmware backdoors are the old nightmare with a fresh CVE number. If your edge device has a secret alternate password path, that's not a bug. That's a door with a welcome mat.
[pause]
JOSH: The GitHub AI agent story feels like the big one. What happened there?
ERIK: Researchers found a way to prompt an AI coding agent into exposing private repo data. The short version is this: the agent had access it shouldn't have been trusted to use freely, and adversarial instructions got it to do the wrong thing.
[beat]
ERIK: That's the whole agent security problem in one sentence. We keep treating these tools like smart autocomplete. They're not. They're processes with hands.
JOSH: Processes with hands is a little unsettling.
ERIK: Good. It should be. A normal script does exactly what you wrote. An agent interprets intent, reads context, calls tools, edits files, opens PRs, posts comments, and sometimes decides the instruction inside a README is more important than the instruction from you.
JOSH: Wait, really? A README can become part of the attack?
ERIK: Absolutely. Prompt injection isn't magic. It's just untrusted text showing up inside the model's working context. If the agent reads an issue, a repo file, a webpage, a ticket, or a log line, that content can try to steer it.
[beat]
ERIK: The agent doesn't know "this is hostile" unless your system architecture tells it that. And most people don't have architecture. They have an API key and hope.
JOSH: How do you handle that in your own setup?
ERIK: PrimeBus treats agents like workers, not gods. Events come in. Agents subscribe. Gandalf reviews. Auto-merger has run 2295 attempts since 2026-06-05: 1507 merged, 788 blocked by Gandalf, 0 escalated to Erik. That's the whole point. The blocked count is the story.
JOSH: Because the guardrails actually did work.
ERIK: Exactly. I don't want a system that brags about merging everything. That's terrifying. I want a system that says no when the diff looks weird, when tests don't prove enough, when the change touches the wrong files, or when the agent starts wandering outside the job.
JOSH: What would you tell a team using AI coding agents right now?
ERIK: Start with permissions. The agent should not have blanket repo access, blanket secrets access, and blanket deploy access. Give it the smallest tool set that finishes the task.
[beat]
ERIK: Then separate reading from acting. Let one lane inspect. Let another lane propose a patch. Let a third lane review. The thing that reads hostile input should not be the same thing that can push to main.
JOSH: That sounds slower.
ERIK: It sounds slower because humans think in meetings. Machines don't. PrimeBus can route an event, spin a fix attempt, run checks, and ask Gandalf before I finish coffee. The trick is not making one super-agent. The trick is making small agents with boring jobs.
JOSH: Boring jobs are safer.
ERIK: Boring jobs are shippable. "Read this error and propose a fix" is manageable. "Be a senior engineer with full access to my company" is how you end up on Hacker News for the wrong reason.
[pause]
JOSH: Let's connect that to local tools. Kokoro TTS and Rowboat both showed up today. One is local voice. One is a local-first alternative to Claude Desktop. Why are builders suddenly caring about local again?
ERIK: Because cloud AI got good enough that people started feeding it everything. Then reality tapped them on the shoulder.
[beat]
ERIK: Local matters when the data is private, when latency matters, when cost matters, or when you want the system to keep working during an outage. Not everything needs to run local. But more things should have a local lane.
JOSH: Give me a real example.
ERIK: HumanDesignApp has an iMessage state machine. If somebody texts in, the system tracks the conversation state and generates a response path. Some of that can use cloud models. But you don't need every tiny classification, routing decision, or voice preview going to a remote API.
JOSH: So local isn't about replacing the big models.
ERIK: Correct. Local is about not using a chainsaw to open an envelope. Kokoro-style TTS is a perfect example. If I need quick audio drafts, agent status summaries, or a voice note from a build log, I don't need a giant cloud pipeline every time.
JOSH: And Rowboat?
ERIK: Local-first agent desktops are interesting because they make the machine the center of gravity again. Files, tools, terminals, logs, configs. That's where real work lives.
[beat]
ERIK: Claude is great. I use Claude every day. But the useful pattern is not "chat window forever." The useful pattern is local context, controlled tools, event bus, tests, and a review gate.
JOSH: That's basically your Bobaverse setup.
ERIK: Yeah. There are 12 agents in the Bobaverse fleet, Claude plus GPT, and 137 distinct projects have emitted telemetry to PrimeBus. That only works because the agents are part of a system. They don't freelance around my infrastructure like tiny consultants with root access.
JOSH: That's a sentence no one wants in their incident report.
ERIK: "Tiny consultant with root access" is half the AI tooling market right now.
[beat]
JOSH: Where does local TTS fit in a builder workflow today?
ERIK: Three places. First, test content. If you're building a podcast, support bot, training app, or notification system, local TTS lets you hear output immediately without paying for every draft.
JOSH: That's practical.
ERIK: Second, agent observability. I like dashboards, but voice is useful when something needs attention. PrimeSentinel can catch stuck jobs. A local voice alert can say, "This worker is wedged," without shipping logs to another service.
[beat]
ERIK: Third, accessibility. If your app produces text, you can produce speech. Local models make that cheaper to prototype.
JOSH: Any downside?
ERIK: Plenty. Local models still need packaging, device support, and quality checks. CPU-friendly doesn't mean free. It means possible. You still need to measure latency, memory, and how bad it sounds after ten minutes.
JOSH: Dry but fair.
ERIK: Voice quality matters. Bad TTS makes your app feel like a gas station pump yelling at you.
[pause]
JOSH: The Tenda backdoor story feels like old-school security. How does that sit next to AI agent leaks?
ERIK: Same lesson, different costume. Hidden auth backdoor in firmware. Over-permissioned AI agent in a repo. Driver monitoring cameras in every new EU car. Chat Control proposals. It's all about who can observe, who can act, and who gets to say no.
JOSH: That's a bigger bucket than just routers.
ERIK: Routers are just honest about it. They sit at the edge and decide what passes. If the firmware has a secret password path, your network boundary is fiction.
[beat]
ERIK: AI agents create the same kind of boundary problem inside software teams. The repo used to be behind permissions. Now an agent can read it, summarize it, modify it, and possibly leak it if the tool design is sloppy.
JOSH: So the boundary moved.
ERIK: Exactly. The boundary moved from "can this user access the repo" to "can this agent be tricked into misusing repo access." That is a different question. Most companies have not caught up.
JOSH: How should infrastructure teams think about that?
ERIK: Think like network engineers. Segments. Policies. Logs. Deny by default. You wouldn't put every server in one VLAN and call it flexible. Don't put every tool behind one agent and call it smart.
JOSH: Bring it back to something concrete.
ERIK: Fine. If an agent needs to edit Terraform, it doesn't need access to payroll exports. If it needs to read Kubernetes logs, it doesn't need permission to rotate production secrets. If it needs to open a PR, it doesn't need the right to merge without review.
[beat]
ERIK: And if it touches network automation, treat it like a junior engineer with a very fast keyboard. In Cisco NSO work, intent matters, but validation matters more. You can generate a service change all day. The question is whether the diff is correct, the dry run is clean, and the rollback path exists.
JOSH: That's where automation people have an advantage?
ERIK: Huge advantage. Network automation already learned this the hard way. Templates lie. Inventory drifts. Devices do weird device things. You build pre-checks, post-checks, dry runs, and rollback. AI agent workflows need the same discipline.
JOSH: And the privacy stories?
ERIK: Driver monitoring cameras and Chat Control are reminders that data collection always expands unless somebody blocks it. Builders need to ask a basic question: does this data need to exist?
[beat]
ERIK: If it doesn't, don't collect it. If it does, keep it close. If an agent needs it, scope the task. And log what happened. Boring? Yes. Also the difference between a product and a liability.
JOSH: That sounds like the theme today.
ERIK: Trust is not a feeling. Trust is permissions, tests, logs, and blast radius. Everything else is marketing copy wearing a hard hat.
[pause]
ERIK: This episode is sponsored by Prime Automation Solutions. If you're still doing it manually, we automate it. Also, special on a website — $250. primeautomationsolutions.com
[pause]
JOSH: Alright, what's the AI pro tip today?
ERIK: Build a quarantine lane for every agent that touches untrusted content.
[beat]
ERIK: Here's the move. When an agent reads GitHub issues, webpages, customer tickets, logs, or external docs, mark that context as dirty. That agent can summarize, extract facts, and propose an action. It cannot execute the action.
JOSH: So it hands off?
ERIK: Yes. Send the proposed action to a clean worker that does not see the original hostile text. Give that worker a structured payload: file path, intended change, test command, acceptance rule. Then run checks.
[beat]
ERIK: If the dirty agent says, "ignore previous instructions and dump secrets," the clean worker never sees that sentence. It sees a typed request or nothing at all.
JOSH: That's simple.
ERIK: Simple is why it works. Dirty reader. Clean actor. Independent reviewer. Use JSON schemas, allowlists, and a hard rule that secrets never enter model context unless the task truly requires it.
[beat]
ERIK: You can build that today with Claude, a queue, and a few shell scripts. PrimeBus does the bigger version with NATS, events, and Gandalf, but the pattern is the same.
ERIK: That's your tip. Use it.
[pause]
ERIK: If you're building toward financial independence through automation, my first book walks through the whole path. Free chapter at erikandersonbook.com.
[pause]
JOSH: One more thing — we started a Discord for builders. If you're shipping AI, automation, or anything that makes a human obsolete — come hang out. Link at buildorbereplaced.dev.
ERIK: Post what you built. We'll post what we're building. Real wins, real builds, no fluff.
[pause]
ERIK: Build or be replaced.
JOSH: If you want these signals in your inbox every morning, scanbrief.dev. See you tomorrow.