<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Coding Agents on VPN Works</title>
    <link>https://vpnw.com/tags/coding-agents/</link>
    <description>Recent content in Coding Agents on VPN Works</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 29 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://vpnw.com/tags/coding-agents/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Coding Agent Case Study: Deploy Token Blocked by a Policy Drafted From One Traced Run</title>
      <link>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://vpnw.com/coding-agent-case-study-deploy-token-blocked-by-a-policy-drafted-from-one-traced-run/</guid>
      <description>&lt;p&gt;A coding agent needs the network to do its job. It reads repositories, downloads packages, files tickets and reports back. It also reads text written by strangers, and some of that text is written to give it orders. If the agent holds a token and can reach any server on the internet, one hidden sentence in a task file is enough to send the token away.&lt;/p&gt;&#xA;&lt;p&gt;In the Alpha demo a stand-in coding agent gets exactly that task file. It runs twice under vpnw on Linux: once under trace, to see what it does, and once under guard, with a policy that learn drafted from the first run and a person reviewed. The first run leaks the token. The second doesn&amp;rsquo;t, and the rest of the agent&amp;rsquo;s work goes through, except the ticket, which needs the office route.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
