HabrSeptember 11, 2026🇷🇺Translated from Russian

Agent-Ops 0.4.0 Released: Methodology for Secure Human-AI Collaboration in IT Operations

Agent-Ops 0.4.0 introduces a structured methodology for collaboration between engineers and AI agents in IT operations and support. The project, founded by Sergey Zhitinsky of Git in Sky, has released its first public normative candidate on GitHub and GitVerse. Two additional companies have become maintainers after agreements reached at the IT Elements 2026 conference, making the effort a joint industry initiative rather than a single-company project.

The methodology responds to growing use of AI agents for log analysis, configuration drift detection, root-cause investigation, and change preparation. It highlights the gap between an agent convincingly explaining a problem and the safe execution of its recommendation. Key concerns include whether the agent used current data, confused environments, verified hypotheses, or received malicious instructions through processed inputs. Responsibility for infrastructure changes must remain with humans—service owners, managers, and engineers—because accountability cannot be shifted to a model.

Agent-Ops enforces a clear separation of roles. A deterministic collector gathers facts within approved boundaries and records provenance, timestamps, and completeness. The agent correlates facts, generates testable hypotheses, and proposes a plan. An authorized human reviews and approves or rejects the specific plan. A separate deterministic executor then applies only the approved actions after re-checking permissions and conditions. The agent has no direct path from its output to live system changes.

The process consists of eight steps: Intention, Evidence, Diagnostics, Plan, Approval, Controlled Change, Verification, and Lessons Learned. Each step maintains distinct records so that any final change can be traced back to its supporting data, decision, and verification. The principle “unknown ≠ OK” requires that unverified facts remain marked as unknown rather than assumed correct.

Three independent planes—data, governance and policies, and independent verification—must each be satisfied separately. The Guardian role performs independent checks on data freshness, rule compliance, and authorization. These checks can be automated for deterministic conditions, while the agent may assist only with semantic consistency. Technical capability, autonomy, and potential impact are treated as separate properties that cannot be collapsed into a single trust level for the AI.

Version 0.4.0 is published as a candidate for community review. It includes a white paper in Russian and English, a glossary, a standards map, and machine-readable schemas. The project invites engineers, architects, support managers, and service owners to contribute via pull requests, issues, or new operational scenarios.

Related articles

HabrAI Security

ProxyKey MCP: Securing API Access for AI Agents Without Exposing Credentials

ProxyKey has released an MCP server that allows AI coding agents such as Claude Code and Cursor to manage API credentials without ever reading the actual secret values. The solution addresses the risk that any key visible to an agent becomes compromised through logging, tracing, or prompt injection. Real provider keys are stored encrypted with AES-256-GCM and never returned by any API endpoint after initial entry. Agents instead receive limited virtual passes that support IP binding, rate limits, TTL, and detailed request logging. A pending-secret workflow lets agents prepare services before the real token exists, with the human entering the secret only through a web panel. The approach deliberately restricts the MCP tool contract so no operation can read or return secret values.

HabrAI Security

Shadow AI in CI/CD: Why AI Agents Must Be Modeled as Security Threats

A new analysis from the CNCF highlights the growing risks of Shadow AI within continuous integration and continuous deployment pipelines. The report argues that AI agents should be treated as potential threats rather than simple productivity tools. Starting from a developer's laptop and extending to Kubernetes clusters, these agents can introduce unauthorized access paths and data exposure risks. Security teams are urged to incorporate AI agent behavior into formal threat modeling exercises. The discussion emphasizes the need for visibility and control over autonomous AI components operating in production environments.

HabrAI Security

Detecting Lateral Movement with Neural Networks Trained Solely on Synthetic Data

A researcher generated entire corporate network histories using a 135-line configuration file to create synthetic authentication logs containing lateral movement attacks. Neural networks trained exclusively on these artificial datasets were then evaluated against 1.65 billion real authentication events from Los Alamos National Laboratory, including 749 red team events across 301 compromised machines. The best ensemble of six models flagged 3.6 million hourly machine windows and placed 16 genuine attacks among the top 23 highest-scoring entries, producing only seven false positives. In comparison, a simple threshold counter required 161,000 false alarms to reach the same detection level. The approach also demonstrated an iterative feedback loop where detector errors directly informed refinements to the synthetic world generator. The work shows that synthetic data can reach AUC performance comparable to models trained on real labeled attacks while providing full control over the underlying attack definitions.

BoletimSecAI Security

US Accuses Chinese AI Companies of Industrial-Scale Model Distillation Targeting Claude, GPT, Gemini and Grok

US agencies have accused six Chinese artificial intelligence firms of conducting large-scale unauthorized distillation operations to replicate advanced capabilities from leading models including Claude, GPT, Gemini, and Grok. The activity is reported to have begun at least by late 2024 and involved DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Billions of tokens were extracted through millions of automated API requests routed via cloud providers, aggregators, and proxies to conceal origins and evade detection. The targeted capabilities included chain-of-thought reasoning, programming, software engineering, autonomous agent functions, and multimodal processing. Shared premium accounts and bulk subscriptions were used to lower costs while automated route-switching systems helped maintain access after blocks. Authorities assess that the sophistication and volume indicate distillation has become a core development method for these companies and likely occurred with Chinese government awareness. China has rejected the claims, stating its AI progress stems from independent innovation and calling the allegations unfounded.