<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Tokenise</title><link>https://tokenise.rosvetic.com/categories/security/</link><description>Recent content in Security on Tokenise</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 08 Oct 2026 13:41:00 +0000</lastBuildDate><atom:link href="https://tokenise.rosvetic.com/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>GitHub's new secret-detection model catches passwords that regex can't. Check the billing before you opt in</title><link>https://tokenise.rosvetic.com/posts/github-ai-secret-detection-model/</link><pubDate>Thu, 08 Oct 2026 13:41:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/github-ai-secret-detection-model/</guid><description>&lt;p&gt;GitHub has swapped the engine behind its AI-detected secret alerts for a purpose-built model, and it&amp;rsquo;s now using the same model for two new checks aimed at the places agent-written code tends to leak: the push, and the review. The details are in &lt;a href="https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection/" target="_blank" rel="noopener noreferrer"&gt;GitHub&amp;rsquo;s changelog entry for October 7&lt;/a&gt;&#10;.&lt;/p&gt;</description></item><item><title>Copilot's local sandboxing is GA. Here's what it actually restricts</title><link>https://tokenise.rosvetic.com/posts/copilot-local-sandboxing-ga/</link><pubDate>Thu, 08 Oct 2026 00:01:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/copilot-local-sandboxing-ga/</guid><description>&lt;p&gt;GitHub announced on October 7 that local sandboxing for Copilot is generally available, across the Copilot CLI, the Copilot app and VS Code sessions that use Agent Host. It runs on Windows, macOS and Linux, and it&amp;rsquo;s &lt;a href="https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available" target="_blank" rel="noopener noreferrer"&gt;included with Copilot at no extra cost&lt;/a&gt;&#10;. The changelog is short on detail, so the useful part is in the docs.&lt;/p&gt;</description></item><item><title>Claude Code mods run inside the process with your permissions. Vet them before you install</title><link>https://tokenise.rosvetic.com/posts/claude-code-mods-vet-before-install/</link><pubDate>Tue, 06 Oct 2026 16:02:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/claude-code-mods-vet-before-install/</guid><description>&lt;p&gt;Claude Code 2.1.287 introduced mods: plugins whose JavaScript or TypeScript functions run inside the Claude Code process. They can draw panes, rewrite tool calls and add commands. They also run with your permissions and sit outside the sandbox, which makes &amp;ldquo;read it before you install it&amp;rdquo; a real step rather than a platitude.&lt;/p&gt;</description></item><item><title>Codex can hand its approval prompts to a reviewer agent. Here's how to set it up</title><link>https://tokenise.rosvetic.com/posts/codex-auto-review-approvals/</link><pubDate>Tue, 06 Oct 2026 07:06:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/codex-auto-review-approvals/</guid><description>&lt;p&gt;Codex can stop asking you to approve every escalated command and let a second agent decide instead. It&amp;rsquo;s called auto-review, it&amp;rsquo;s a two-line config change, and it only helps if you understand what it does and doesn&amp;rsquo;t cover.&lt;/p&gt;</description></item><item><title>A PreToolUse hook is the guardrail that survives bypass mode</title><link>https://tokenise.rosvetic.com/posts/claude-code-pretooluse-guardrail-hook/</link><pubDate>Mon, 05 Oct 2026 22:30:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/claude-code-pretooluse-guardrail-hook/</guid><description>&lt;p&gt;Permission prompts are only as strong as the mode you&amp;rsquo;re running in. Switch to bypass mode, or launch with &lt;code&gt;--dangerously-skip-permissions&lt;/code&gt;, and the prompts are gone. A PreToolUse hook is different: according to the Claude Code &lt;a href="https://code.claude.com/docs/en/hooks-guide" target="_blank" rel="noopener noreferrer"&gt;hooks guide&lt;/a&gt;&#10;, it fires before any permission-mode check, and a &lt;code&gt;deny&lt;/code&gt; from it blocks the tool even in &lt;code&gt;bypassPermissions&lt;/code&gt; mode.&lt;/p&gt;</description></item><item><title>Claude Code's auto mode catches most risky actions. Anthropic's numbers show what it misses</title><link>https://tokenise.rosvetic.com/posts/claude-code-auto-mode-numbers/</link><pubDate>Sat, 03 Oct 2026 07:00:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/claude-code-auto-mode-numbers/</guid><description>&lt;p&gt;Anthropic published how Claude Code&amp;rsquo;s auto mode works, with measured error rates. That&amp;rsquo;s unusual for a security feature, and it makes the engineering post worth reading before you let an agent run unattended. The &lt;a href="https://www.anthropic.com/engineering/claude-code-auto-mode" target="_blank" rel="noopener noreferrer"&gt;full write-up&lt;/a&gt;&#10; is on Anthropic&amp;rsquo;s engineering blog.&lt;/p&gt;</description></item><item><title>Cursor's Security Review bot reads your pull requests for exploitable bugs</title><link>https://tokenise.rosvetic.com/posts/cursor-security-review-bot/</link><pubDate>Thu, 01 Oct 2026 12:00:00 +0000</pubDate><guid>https://tokenise.rosvetic.com/posts/cursor-security-review-bot/</guid><description>&lt;p&gt;Cursor launched a Security Review bot on September 23, alongside the Rollouts deploy monitor we covered in &lt;a href="https://tokenise.rosvetic.com/posts/cursor-rollouts-bot-watches-deploys/"&gt;an earlier post&lt;/a&gt;&#10;. It reads pull requests and reports vulnerabilities an attacker could actually exploit. Per the &lt;a href="https://cursor.com/changelog/rollouts-and-security-reviewer" target="_blank" rel="noopener noreferrer"&gt;Cursor changelog&lt;/a&gt;&#10;, it&amp;rsquo;s on Teams and Enterprise plans.&lt;/p&gt;</description></item></channel></rss>