AI Agents
Browse all articles, tutorials, and guides about AI Agents
Posts
A Poisoned .git/config Runs Code on git status. We Tested Which Commands and Copies Carry It
On October 2 GitLab disclosed ConfigPoisoning: a repo that brings its own .git/config makes an AI coding tool run attacker commands when it shows a diff. We ran the same trick against plain git 2.39 and 2.55. A bare git status ran repo-supplied programs, the usual safe diff flags missed the clean filter, git 2.54 config hooks walked past core.hooksPath=/dev/null, a clone was clean but a cached workspace was not, and GitHub-hosted runners switch off the ownership check that would stop it.
A Repo per Agent: What Cloudflare Artifacts Changes About Git
Cloudflare Artifacts gives every agent, session or task its own Git repository. We measured how push contention grows when agents share one branch, walked through the Workers API, and priced the pattern so you can decide where it fits.
Issue to Pull Request with DigitalOcean Managed Agents
We gave an OpenCode agent on DigitalOcean Managed Agents three real GitHub issues and no GitHub token. It produced three merged pull requests and one wrong one that passed its tests. Here is the setup, the recorded runs, the cost per issue, and every gotcha we hit.
Where to Run AI Agents: 8 Managed Agent Runtimes Compared
DigitalOcean Managed Agents, Cloudflare, AWS AgentCore, Google, Microsoft Foundry, E2B, Vercel and Modal, compared on isolation, state, tool access, limits and price, with one cost scenario worked out on every platform.
One Key for Claude, GPT, and Gemini: the Gateway Pattern
Using three model providers usually means three API keys, three SDKs, and three billing relationships sprayed across your code. An AI gateway collapses that to one credential and one OpenAI-compatible endpoint. I proved it on a Neon Function: the same call answered by GPT, Claude, and Gemini.
A Postgres-Backed MCP Server in ~20 Lines
Most of what an MCP server does is run database queries on behalf of an AI agent. So I put one right next to the database. Here is a Postgres-backed MCP server built on Neon Functions, deployed onto a database branch, with the code, a live client test, and the repo.
Streaming an AI Agent Without a Function Timeout
Long agent loops and long token streams run into the same wall: a serverless function that hits its execution cap and cuts the connection. Neon Functions hold long-lived streaming connections by default. I deployed two endpoints to prove it: one streamed for 90 seconds, the other streamed an agent token by token starting at 466 ms.
I Gave an AI Agent a Database, Compute, Storage, and Models From One CLI
An AI agent usually needs four accounts: a database, somewhere to run, object storage, and a model provider. I wired all four from a single Neon credential and had a deployed image-generating agent in a few minutes. Here is the actual build log, the config that ties it together, and the honest caveats.