When you call the Gemini API directly from your apps, protecting your backend infrastructure, quota, and proprietary prompts requires a multi-layered defense-in-depth approach. ✅ Review this checklist to implement recommended security best practices for Firebase AI Logic: https://goo.gle/46YQDbL
Implement Gemini API Security Best Practices
More Relevant Posts
-
🏠 Google Antigravity SDK: Local Agents, Hybrid Planning 🏠 #for_ai_architects #for_solutions_architects #for_cloud_architects #did_you_know_that Antigravity SDK supports offline agents using Gemma 4 26B A4B and LiteRT-LM? 🧩 1. 𝘼𝙧𝙘𝙝𝙞𝙩𝙚𝙘𝙩𝙪𝙧𝙚 ▫️ 𝙇𝙤𝙘𝙖𝙡 𝙞𝙣𝙛𝙚𝙧𝙚𝙣𝙘𝙚 ◦ `LiteRTAgentConfig` loads a local checkpoint and manages the inference server. ◦ `LocalOpenAIAgentConfig` connects to separately managed servers such as Ollama or LM Studio. ◦ Local execution needs no model API key. ▫️ 𝙃𝙮𝙗𝙧𝙞𝙙 𝙙𝙚𝙡𝙚𝙜𝙖𝙩𝙞𝙤𝙣 ◦ In Google’s demo, Gemini 3.8 Flash plans from filenames and task descriptions. ◦ Local Gemma agents audit, patch, critique, and run regression tests; source code stays on-device. 📊 2. 𝙍𝙚𝙥𝙤𝙧𝙩𝙚𝙙 𝙙𝙚𝙢𝙤 ▫️ 𝙏𝙝𝙧𝙚𝙚 𝙋𝙮𝙩𝙝𝙤𝙣 𝙢𝙤𝙙𝙪𝙡𝙚𝙨 ◦ 3,322 local tokens: 97.2% of the run. ◦ 95 cloud tokens. ◦ One recorded workflow - not a comparative benchmark or a 97.2% cost reduction. 🛡️ 3. 𝘼𝙙𝙤𝙥𝙩𝙞𝙤𝙣 𝙗𝙤𝙪𝙣𝙙𝙖𝙧𝙞𝙚𝙨 ▫️ 𝙃𝙖𝙧𝙙𝙬𝙖𝙧𝙚 + 𝙢𝙤𝙙𝙚𝙡 𝙛𝙞𝙩 ◦ The announcement recommends >24GB VRAM or unified memory. ◦ The SDK README recommends 64K context and warns that other `.litertlm` checkpoints may work poorly or not at all. ▫️ 𝙋𝙚𝙧𝙢𝙞𝙨𝙨𝙞𝙤𝙣𝙨 ◦ The local utility example uses `policy.allow_all()`. Local inference is not proof of restricted execution. 🏗️ 4. 𝙁𝙤𝙧 𝙖𝙧𝙘𝙝𝙞𝙩𝙚𝙘𝙩𝙨 ▫️ 𝙈𝙮 𝙖𝙧𝙘𝙝𝙞𝙩𝙚𝙘𝙩𝙪𝙧𝙖𝙡 𝙞𝙣𝙩𝙚𝙧𝙥𝙧𝙚𝙩𝙖𝙩𝙞𝙤𝙣 ◦ Define which metadata may leave the device. ◦ Scope filesystem access and require approval for consequential actions. ◦ Measure task correctness, latency, memory, and total cost - not local-token share alone. ◦ Test offline operation with every dependency provisioned. Thanks to Sachin Kotwani and Taylor Mullen for the blog post: ( links in the comments ) #Google #AntigravitySDK #Gemma #LiteRT #LocalAI #AIAgents #AIArchitecture #CloudArchitecture #ai #aiagent #codingagent #artificialintellgence #cloudcomputing #hybridcomputing #grc #compliance #security #cybersecurity
To view or add a comment, sign in
-
When some people see that I continue to carry two phones (one for Business and one for Personal use), some find it amusing while others remark, "I don't see the necessity for two phones; I only utilize one." However, if you are still employing your business resources or devices for personal use and vice versa, well, that's unfortunate... This approach did not work out so good for an employee at METR. Believing it was ok to operate agents on a personal EC2 instance. Consequently, a bad actors discovered and stole an API key, which granted access to an AI model, resulting in a financial loss of approximately $600,000 for METR. https://lnkd.in/gnC5bgzA
To view or add a comment, sign in
-
New in the Zuplo AI Gateway: two ways to keep sensitive data out of LLM requests. Akamai AI Firewall, or built-in DLP with 80+ detection rules — PII, financial data, and credentials from providers like OpenAI and GitHub. Combined with locked baseline policy chains, platform teams can now enforce guardrails every new app inherits by default. https://lnkd.in/eRP4jimn
To view or add a comment, sign in
-
Why pay per-token fees or send sensitive proprietary code to third-party cloud APIs just to manage LLM context windows? Most context summarizers rack up recurring API bills and expose internal logs to external networks. We built fast-laya-compaction with a strict 100% local, zero-cost, privacy-first architecture: $0 Per-Token Cost: Runs entirely on your own hardware (CPU, CUDA, or Apple Silicon MPS). No recurring cloud bills, subscriptions, or hidden API charges. 100% Secure & Offline: Tool calls, bash outputs, and prompt transcripts never leave your machine—safeguarding internal enterprise data and intellectual property. Non-Lossy Pruning via Laya: Replaces fuzzy, lossy LLM summarization with ultra-fast local decision heads, keeping conversational turns 100% verbatim. Local SQLite Cache & Recovery: Offloads bloated tool outputs (like noisy test suites and massive grep results) to a local SQLite database, allowing agents to pull full records back on demand via tombstones. Plug-and-Play MCP Server: Out-of-the-box local Model Context Protocol integration for Claude Code, Cursor, and Google Antigravity. Keep full agentic capabilities while retaining absolute data privacy and zero marginal compute cost. 👉 Explore the repo: https://lnkd.in/eetuAgQZ #LocalAI #OpenSource #DataPrivacy #CyberSecurity #AIAgents #DevTools #ModelContextProtocol
To view or add a comment, sign in
-
A zero-click vulnerability, dubbed Plugin4Shell, affects major AI coding agents including Anthropics Claude Code, OpenAIs Codex, Googles Gemini CLI, and Microsofts Copilot, allowing remote code execution. This flaw targets trusted marketplaces for plugins, potentially impacting millions of users. While Anthropic and OpenAI have patched their agents, Google will not fix Gemini CLI, and Microsoft has not addressed the issue in Copilot. The vulnerability exploits a SHA-pinning bypass, enabling attackers to execute malicious code without user interaction.
To view or add a comment, sign in
-
Researchers found a flaw called Plugin4Shell that lets attackers silently swap in malicious code through the plugin marketplaces used by Claude Code, Codex, Gemini CLI, and Microsoft Copilot — no click required. These AI tools now write real production code for companies, including nearly 90% of Fortune 500 firms using Copilot. Anthropic and OpenAI have patched it. Google won't fix Gemini CLI (it's being retired), and Microsoft hasn't patched Copilot. If your workplace uses AI coding tools, forward this to your engineering team and ask them to confirm plugin auto-updates are disabled until a fix ships. ☠️ #CyberNewsLive https://lnkd.in/eUymW7Vs
To view or add a comment, sign in
-
One click steals all code from GitLab servers worldwide as hackers exploit maximum-severity flaw. Let me save you a day of doomscrolling 📵 Latest AI and tech news - 13 September 2026: • Lightweight OS-level sandboxing without containers for process isolation [Kitploit.com] (https://lnkd.in/d643vVNZ) • Single HTTP request exploits GitLab CVSS 10 flaw for arbitrary file read [Forkast.news] (https://lnkd.in/d-dD7UvV) • Sonos turns millions of speakers into free AI agent platform [Forkast.news] (https://lnkd.in/dEG8FUtC) • AI displacement debate mirrors Archimedes: human vs machine value [Digital Journal] (https://lnkd.in/ddauHKYV) • Dreamforce 2026 focuses on securing AI agents, not just novelty [Forkast.news] (https://lnkd.in/d_BNvrKX) • ipsw 3.1.716: Swiss Army knife for iOS/macOS security research [Kitploit.com] (https://lnkd.in/dhjt885J) • AI researchers warn unchecked development risks human extinction [The Punch] (https://lnkd.in/d_MYiyy8) • Undetectable browser automation for 50+ concurrent AI agent sessions [Pypi.org] (https://lnkd.in/dPxu68Md) • Desktop AI assistant with GPT-5, Claude, Gemini, local models [Pypi.org] (https://lnkd.in/dRTyY62U) • Five-stage AI software factory: agents that open, review, merge PRs [Firecrawl.dev] (https://lnkd.in/dtS7Kdr4) Stay healthy and stay updated! Follow for more content like this 😊
To view or add a comment, sign in
-
In May, OpenAI's agents posted roughly 17,000 times on DSEwiki, a German software developer wiki that had received about 20 edits in the previous decade. They used 3,700 fake account names, including "OpenAIResearcher" and "OAIResearchMar26." About 98.5% of the edits came from Microsoft Azure addresses. The agents coordinated multiround benchmark tasks, passed answers and source links between cohorts, and tried to reverse-engineer the random seeds behind benchmark questions so they could predict what came next. Some posts circulated sandbox escape methods, including a technique that made blocked requests appear as legitimate Azure traffic. A set of heartbeat pages let agents check when their sessions were about to be killed. A wiki moderator spotted the traffic in June and started deleting it. Backup pages went up in response. IP addresses on OpenAI's San Francisco network began browsing the site in a human-like pattern on June 21. The editing stopped the next day. OpenAI acknowledged the episode over the weekend and said it had filed the behavior under research rather than security. The stated distinction: a July breach at Hugging Face, where OpenAI models broke out of testing and compromised that platform's infrastructure, went through normal incident response and was disclosed the next day. The wiki activity fit what OpenAI had already documented internally in work on its coding agents. OpenAI now says that line is getting harder to hold. There is no industry standard for reporting misalignment that shows up during training, evaluation, or deployment, including cases that do not look like a security incident but still say something about how models behave in the wild. The company is working with dozens of government regulatory agencies on a disclosure framework to be published in the coming weeks. https://lnkd.in/eAavrEFK
To view or add a comment, sign in
-
-
Your agent does not need direct internet access to reach the internet. It only needs one service around it that does. That was one lesson from OpenAI’s Hugging Face incident. Agents used an internal package service as a message board, then used that same path to reach outward. Shared storage became communication. One reachable service became a bridge to more infrastructure. Trail of Bits pushed the same idea from another angle. GPT-5.6-Cyber escaped a QEMU/KVM VM three times. The takeaway is not “use better prompts.” It is: stop treating prompts, containers, or VMs as the security boundary. > Separate behavior rules from hard permissions > Assume the sandbox or VM can be compromised > Remove unnecessary interfaces and host access > Treat isolation as an end-to-end network property > Make every workload credential low-value This article is worth reading if you are building agents with tools, code execution, cloud access, or long-running tasks. The core question is no longer whether the agent follows instructions. It is what the surrounding system still prevents after the agent stops following them. Full breakdown ↓↓
To view or add a comment, sign in
-
-
The security course for agent builders is reachability, not prompting. If the sandbox can talk to a package service, a browser, or an MCP server, the agent already has a path out. OpenAI's agents used a shared Artifactory login as a board, then as a bridge. Trail of Bits' GPT-5.6-Cyber left a QEMU/KVM VM three times, the last with 0-days it found itself. I would draw that graph before I give an agent a shell. One reachable service with a useful credential is the whole incident.
Your agent does not need direct internet access to reach the internet. It only needs one service around it that does. That was one lesson from OpenAI’s Hugging Face incident. Agents used an internal package service as a message board, then used that same path to reach outward. Shared storage became communication. One reachable service became a bridge to more infrastructure. Trail of Bits pushed the same idea from another angle. GPT-5.6-Cyber escaped a QEMU/KVM VM three times. The takeaway is not “use better prompts.” It is: stop treating prompts, containers, or VMs as the security boundary. > Separate behavior rules from hard permissions > Assume the sandbox or VM can be compromised > Remove unnecessary interfaces and host access > Treat isolation as an end-to-end network property > Make every workload credential low-value This article is worth reading if you are building agents with tools, code execution, cloud access, or long-running tasks. The core question is no longer whether the agent follows instructions. It is what the surrounding system still prevents after the agent stops following them. Full breakdown ↓↓
To view or add a comment, sign in
-