Secure your Virtual Private Server (VPS)
A virtual private server gives an AI agent a dedicated place to work, separate from your personal computer. But an agent can still misunderstand a task, delete valuable work, or follow malicious instructions hidden in a document. Set up the server so that mistakes have limited consequences.
Start with a supported operating system, regular security updates, and only the software you need. Run the agent in a restricted environment, such as a container, without administrator access to the host. Give it only the files and tools it needs, and keep control of its permissions and security settings outside its reach. Written instructions alone cannot enforce these boundaries.
Keep remote administration private. Use a private remote-access service, such as Tailscale, and restrict access to approved people and devices. Protect the account controlling that access with strong multifactor authentication. Check the access rules rather than assuming that joining a private network makes every connection safe.
Give the agent no unrestricted internet access. Allow only the external services needed for its task, and keep software installation under separate administrative control. An approved connection can still carry sensitive information: sending source code to a cloud model is a disclosure, even when the destination is legitimate. Decide what information may leave before enabling that connection.
Keep administrative passwords and recovery codes in an external password manager, outside the VPS. Store service credentials separately from the agent’s workspace, and avoid placing them in prompts, project files, or logs. Limit each credential’s permissions, prefer access that expires, and make it easy to revoke. An external vault offers little protection if the agent can freely read everything inside it. OWASP explains these credential-management principles.
Decide which actions require your approval. Drafting code should not automatically grant permission to publish it, delete production data, or change account access. Approvals should identify the actual action and target. Keep a human-controlled way to stop the agent and withdraw its access. OWASP’s agent-security guidance covers these boundaries.
Finally, limit resource use and spending, keep activity records somewhere the agent cannot alter, and maintain encrypted backups it cannot delete. Test restoring those backups. Recheck restrictions after updates and restarts. These measures reduce the damage an agent can cause; they cannot guarantee correct work or prevent every attack. Start with small tasks and expand access only when experience shows it is needed.