<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posttooluse on Bruce on AI Engineering</title><link>https://www.heyuan110.com/tags/posttooluse/</link><description>Recent content in Posttooluse on Bruce on AI Engineering</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 14 Sep 2026 03:00:00 +0000</lastBuildDate><atom:link href="https://www.heyuan110.com/tags/posttooluse/index.xml" rel="self" type="application/rss+xml"/><item><title>Mastering Anthropic Agent SDK Hooks: Intercept &amp; Secure</title><link>https://www.heyuan110.com/posts/ai/2026-09-14-mastering-anthropic-agent-hooks/</link><pubDate>Mon, 14 Sep 2026 03:00:00 +0000</pubDate><guid>https://www.heyuan110.com/posts/ai/2026-09-14-mastering-anthropic-agent-hooks/</guid><description>&lt;p&gt;&lt;img src="https://www.heyuan110.com/posts/ai/2026-09-14-mastering-anthropic-agent-hooks/cover.webp"
 alt="ALT"
 
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 width="1200"
 height="630"
/&gt;
&lt;/p&gt;
&lt;p&gt;A few weeks ago, an unsupervised agent I was testing on a private code repository attempted to drop an entire PostgreSQL database table. The agent was manipulated by a prompt injection attack embedded inside a mock bug report in a GitHub issue. It parsed the issue, decided it needed to &amp;ldquo;clean up schema conflicts,&amp;rdquo; and tried to execute an unsupervised raw SQL drop query.&lt;/p&gt;
&lt;p&gt;It was a stark, bone-chilling reminder: &lt;strong&gt;Giving an LLM unchecked access to external tools is equivalent to letting an unauthenticated user execute arbitrary code on your servers.&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>