◉ TRUST3 LABS
Engineering
Every post, tool release, and field note from the Trust3 research team.
The 3 Layers of Agent Enforcement: Where Your SSH Key Actually Leaks
TL;DR Scope is pro-code agents (Claude Code, Codex, Cursor, Cline) on a developer’s machine, not no-code platforms. Infrastructure controls don’t apply to…
Policy the Agent Reads Is Not Policy the Agent Enforces: Build-Time Configuration ≠ Runtime Enforcement
TL;DR Build-time configuration is the necessary starting point for agent security, but visibility into an agent’s config is not control over its…