RSSAmplifier

Blog

Pyry Haulos — Blog

haulos.comRSS feed ↗10 posts

Latest posts

Why You (Probably) Should Not Give Your Agent GitHub Access

GitHub's security model assumes human users, not prompt-injectable agents. Three design issues, a GraphQL exfiltration vector found by a Claude pentest, and the layered defenses needed to close them.

Scheduled Tasks in Airut

Airut now supports scheduled tasks -- two modes for running Claude Code on a schedule, enabling automated CI fixes, daily briefings, and pipeline refinement.

Building Useful Agents Over Email

Building software, managing accounting, and deploying diagnostics — all by emailing Claude Code through Airut.

Sandboxing AI-Authored Code in GitHub Actions

How writing about agentic AI security revealed a sandbox escape via GitHub Actions, building the fix, and pentesting it with Claude.

Securing Agentic AI Is a Probabilistic Problem

Why agentic AI security can't be solved deterministically, how the industry's current approaches fall short, and two criteria for evaluating practical security.

From One-Shot to Agentic Diagnostic Analysis

How we extended our diagnostics tool from a single-pass analysis pipeline into an agentic workflow where customer support iterates with an AI agent over email to resolve issues.

How XR Became Standard Infrastructure in Defense Training

How Varjo's commercial XR technology became the default choice for high-end military simulation — a dual-use story running in the opposite direction.

Developing with Claude Code over Email

How emailing tasks to Claude Code replaced the terminal interface — and became an open-source project called Airut.

Reflections on AI-Assisted Software Engineering in 2025

How LLMs changed software engineering for me in 2025 — building a 100k-line tool, measured impact, and observations on working with AI coding agents.

Results from Claude Code Pilot at Varjo

What we observed from piloting Claude Code on a large C++ codebase — quantitative results, use cases, limitations, and ROI.