DEV Community

Rudratosh Shastri profile picture

Rudratosh Shastri

Backend architect, 15 years deep. Still curious, still shipping. Systems • AI Agents • Security • Breaking things on purpose 🔥

Education

Studied Computer Science at Arya Institute of IT

Pronouns

He

Work

Technical Lead & Senior Backend Architect at PharmaForceIQ

Your GitHub profile is wallpaper. Mine is a spaceship.

Your GitHub profile is wallpaper. Mine is a spaceship.

9
Comments
8 min read

Want to connect with Rudratosh Shastri?

Create an account to connect with Rudratosh Shastri. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
ELI5: Why can hiding one sentence inside a web page make an AI ignore its own owner and obey a total stranger?

AI lacks an internal sense of authority

ELI5: Why can hiding one sentence inside a web page make an AI ignore its own owner and obey a total stranger?

7
Comments 5
4 min read
6 Ways You're Using Claude Code Like a Chatbot — And What Tech Leads Do Instead

6 Ways You're Using Claude Code Like a Chatbot — And What Tech Leads Do Instead

6
Comments 2
6 min read
Your AI guardrail is green. It's also catching nothing.

Your AI guardrail is green. It's also catching nothing.

9
Comments 24
7 min read
Meta's prompt-injection detector caught 1% of real agent attacks. One config change made it 99%. That's the problem.

Meta's prompt-injection detector caught 1% of real agent attacks. One config change made it 99%. That's the problem.

7
Comments 13
6 min read
'Someone already built that' is a lie. 'It's already secure' is the dangerous one.

'Someone already built that' is a lie. 'It's already secure' is the dangerous one.

6
Comments 2
4 min read
I let AI write my code for a month. The junior devs caught what it broke — I didn't.

I let AI write my code for a month. The junior devs caught what it broke — I didn't.

8
Comments 31
4 min read
Your GitHub profile shows your follower count. It also shows attackers your whole attack surface.

Pins action versions to SHAs for safety

Your GitHub profile shows your follower count. It also shows attackers your whole attack surface.

24
Picked as gem Comments 6
4 min read
Microsoft's own security update broke Ctrl+C in Excel. Here's the patch number, and don't uninstall the first one.

Microsoft's own security update broke Ctrl+C in Excel. Here's the patch number, and don't uninstall the first one.

5
Comments
2 min read
The sandbox had no internet. The AI agent got out through DNS anyway.

The sandbox had no internet. The AI agent got out through DNS anyway.

5
Comments
3 min read
Your GitHub MCP server costs 55,000 tokens before your agent reads a single word.

Prompt caching softens the brutal dollar cost

Your GitHub MCP server costs 55,000 tokens before your agent reads a single word.

9
Picked as gem Comments 26
3 min read
Someone trained a decision model for $104. The price isn't the interesting part — it's that it refuses to write text.

Someone trained a decision model for $104. The price isn't the interesting part — it's that it refuses to write text.

5
Comments
3 min read
Your shopping agent reads the reviews. Attackers write the reviews. Guess who wins.

Your shopping agent reads the reviews. Attackers write the reviews. Guess who wins.

5
Comments 3
3 min read
One prompt to GPT-6 Astra can cost $10. Here's exactly when the 1M context is worth it — and when it's a trap.

One prompt to GPT-6 Astra can cost $10. Here's exactly when the 1M context is worth it — and when it's a trap.

5
Comments
3 min read
Rust quietly ate my JavaScript toolchain in 2026, and my builds are 20x faster for it

Rust quietly ate my JavaScript toolchain in 2026, and my builds are 20x faster for it

5
Comments
3 min read
2025 was about typing faster. 2026 is about knowing what not to build.

2025 was about typing faster. 2026 is about knowing what not to build.

6
Comments
3 min read
AI writes the code. AI reviews the code. So who's actually on the hook when it breaks?

AI writes the code. AI reviews the code. So who's actually on the hook when it breaks?

5
Comments 1
3 min read
Junior developer jobs didn't disappear. The bar for them quietly moved, and nobody sent the memo.

Junior developer jobs didn't disappear. The bar for them quietly moved, and nobody sent the memo.

5
Comments 1
3 min read
"Pinned to a SHA" is a lie your coding agent told you. Here's the Git trick behind Plugin4Shell.

"Pinned to a SHA" is a lie your coding agent told you. Here's the Git trick behind Plugin4Shell.

6
Comments 19
3 min read
An AI Correctly Ignored a Forum Rumor. I Removed One Label and It Paid Out $150.

Kaggle Benchmarking Challenge Submission

An AI Correctly Ignored a Forum Rumor. I Removed One Label and It Paid Out $150.

5
Comments 4
7 min read
I Almost Built a Startup This Week. The Evidence Said No — In One Afternoon.

I Almost Built a Startup This Week. The Evidence Said No — In One Afternoon.

6
Comments 20
5 min read
10 Years In, Everything I Was Proud Of As a Junior Was Wrong

10 Years In, Everything I Was Proud Of As a Junior Was Wrong

5
Comments 2
4 min read
Your AI Agent Will Follow a Stranger's Instructions. Here's How I Actually Test For It.

Your AI Agent Will Follow a Stranger's Instructions. Here's How I Actually Test For It.

5
Comments 4
5 min read
The Hidden Bill: Where AI Agent Costs Actually Come From

The Hidden Bill: Where AI Agent Costs Actually Come From

5
Comments 6
5 min read
I tested 10 prompt-injection detectors on 629 real AI agent attacks

I tested 10 prompt-injection detectors on 629 real AI agent attacks

5
Comments 8
4 min read
Sanity's Knowledge Base stopped 6 of 7 poisoned pages. The 7th fooled Claude Opus 5.

Sanity Challenge Path One Submission

Sanity's Knowledge Base stopped 6 of 7 poisoned pages. The 7th fooled Claude Opus 5.

5
Comments 2
7 min read
AI agents can't tell who's giving the orders. So I built a tiny gate.

AI agents can't tell who's giving the orders. So I built a tiny gate.

11
Comments 8
7 min read
loading...