A three-tier architecture for cheap, injection-safe proactive AI agents

uriwa · reddit · 2026-10-10

Proactive agents that watch your inbox face two walls: cost and security. Since 95% of inbound traffic is noise and a full agent turn costs thousands of tokens, waking the LLM on every webhook can burn $100s/month. Untrusted payloads also invite prompt injection if agents run arbitrary code. The author's three-tier pipeline: (1) a sandboxed edge language (Safescript) with no loops, file access, or shell, and statically analyzed network allowlists; (2) dirt-cheap 'System 1' decision models for classification; (3) the full 'System 2' LLM agent loop reserved for high-value reasoning. Includes sample sandboxed code parsing email fields.

Original post →

More from coding & agent

coding & agent channel →