the gap that comes with it: when gemma 4 makes a function call, there's no verifiable record a human principal authorized it. injected prompt, compromised system instruction, indistinguishable at the tool interface.
built a drop-in middleware using HDP (draft-helixar-hdp-agentic-delegation-00, currently in IETF review):
→ Ed25519-signed delegation tokens issued by the human principal
→ every function call gated before execution
→ irreversibility classification (Class 0 read-only → Class 3 physical actuation)
→ pre-execution audit log
for edge deployments (E2B on raspberry pi + robot arm), HDP-P covers the physical layer
PR open on gemma-cookbook:
https://t.co/KuPU62RqZ5
yesterday, LiteLLM 1.82.8 was pushed to PyPI with a malicious .pth file hidden inside.
97 million downloads/month. caught by a fork bomb bug, not a scanner, not a security tool.
thread on what happened, why it worked, and what stops it 🧵
@BexelInitiative@dr_cintas Getting super cool but scary. I think agentic security is basically going to be be the make or break for projects like these, ensuring the safety nets around what can and can’t be done @Helixar_ai