Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sichere ProgrammierungWe Built a CLI to Find Out If You’re Overpaying for Claude(24.09.2026 um 04:35 Uhr)
•
Sichere ProgrammierungMy own sandbox was killing my agent's shell, and the exit code hid it(24.09.2026 um 04:38 Uhr)
••
Sichere ProgrammierungHow three OSLabs engineers built a CLI to catch you overpaying Claude(24.09.2026 um 04:45 Uhr)
•
Sichere ProgrammierungBreaking CI Guards on Purpose to Prove They Can Fail(24.09.2026 um 05:00 Uhr)
••••
IT Security NachrichtenLangfristige Updatefähigkeit als Pflicht(24.09.2026 um 05:03 Uhr)
••
Sichere ProgrammierungWe Built a CLI to Find Out If You’re Overpaying for Claude(24.09.2026 um 04:35 Uhr)
•
Sichere ProgrammierungMy own sandbox was killing my agent's shell, and the exit code hid it(24.09.2026 um 04:38 Uhr)
••
Sichere ProgrammierungHow three OSLabs engineers built a CLI to catch you overpaying Claude(24.09.2026 um 04:45 Uhr)
•
Sichere ProgrammierungBreaking CI Guards on Purpose to Prove They Can Fail(24.09.2026 um 05:00 Uhr)
••••
IT Security NachrichtenLangfristige Updatefähigkeit als Pflicht(24.09.2026 um 05:03 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

I Added a Live Dashboard to My LLM Proxy. Zero Instrumentation. Just a URL Change.

I built Trooper as a fallback proxy. Claude hits quota → falls back to Ollama. Useful but passive. It sat in the background, invisible, doing its job silently. Today it became something different. The Original Problem When y…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

I built Trooper as a fallback proxy. Claude hits quota → falls back to Ollama. Useful but passive. It sat in the background, invisible, doing its job silently.



Today it became something different.









The Original Problem



When you're building with LLMs, quota hits are inevitable. Claude's free tier is generous until it isn't. A mid-session 429 kills your context, your workflow, your train of thought.



Trooper solved that. Point your app at http://localhost:3000 instead of the Claude API. When Claude fails, Trooper catches it, preserves the full session context via a 3-layer compaction system (Anchor + SITREP + Tail), and continues on local Ollama. Your app never knows anything happened.



That's still there. But it was passive. Useful when things broke. Invisible when they didn't.









The Problem With Passive



Passive infrastructure has an adoption problem. Developers install it, forget about it, and only notice it when something breaks. That's not a product — that's a safety net.



The question I kept asking: what does Trooper do that has daily value, not just failure value?



The answer was sitting in the code the whole time.









What Was Already There



Trooper captures every message in every session. It runs a classifier on each one — extracting intent, entities, open loops, completed steps, recent actions. All rule-based, zero LLM calls, zero latency.



This is what powers the fallback context preservation. When Claude fails and Ollama picks up, Ollama doesn't start blind — it receives a SITREP (Situation Report) that tells it what the session was about, what was completed, what's still pending.



That data exists for every session. It was just never visible to the developer.









The Dashboard



I added a live dashboard at localhost:3000/dashboard.



Point any agent at Trooper — just change your base URL:




export ANTHROPIC_BASE_URL=http://localhost:3000
# or
export OPENAI_BASE_URL=http://localhost:3000






Open the dashboard. Keep it on a second monitor while your agent runs.



From a single message, it already shows:





  • Intent — what your agent is trying to do, extracted automatically


  • Open Loops — what it's stuck on, highlighted in red


  • Completed Steps — what it finished, tracked as it happens


  • Entities — the key things being referenced


  • Session Transcript — every message, colour coded by role



Auto-refreshes every 5 seconds. No page reload needed.









What It Looks Like In Practice





I ran a 3-turn agent session simulating a database debugging workflow:



Turn 1: "I am building a Go API server. The database connection is failing with connection refused errors on port 5432."



Turn 2: "Checked the config. Postgres is running on port 5433 not 5432. Fixing the connection string now."



Turn 3: "Fixed the port. Database connection is working. API server is running successfully."



After Turn 1, the dashboard immediately showed:




  • Intent: "building a go api server. the database connection is failing with connection refused errors on port" (100% confidence)

  • Entities: Postgres, network

  • Open Loops: "fail with connection refused error on port"



After Turn 3:




  • Completed Steps: "successfully fixed the port"

  • Open loops cleared



Zero instrumentation. No SDK. No code changes to the agent. Just a URL change.









Why This Matters



Every observability tool requires you to instrument your code:





  • LangSmith — wrap your agent in LangChain


  • Langfuse — add their SDK


  • AgentOps — add @observe decorators



Trooper requires nothing. Your agent already communicates over HTTP to an LLM. Trooper sits in that path and observes everything automatically.



Helicone was the closest — proxy-based, zero instrumentation. But it went into maintenance mode in March 2026 and was cloud-only. Your data went to their servers.



Trooper is open source, local-first, and free forever. Your data never leaves your machine.









The Sessions Endpoint



Not sure which session to look at? Hit /sessions:




curl http://localhost:3000/sessions
# {"sessions":["agent-debug-123","agent-debug-456"],"count":2}






Click any session in the dashboard home page at localhost:3000/dashboard to open it.









The Recovery Endpoint



Still there. When an agent fails mid-task:




curl http://localhost:3000/recovery/{session_id}






Returns exactly what completed and where to resume. The dashboard makes this visual — completed steps are tracked in real time.









The Pivot



Trooper started as: "Claude failed. Trooper caught it."



Trooper is now: "Your agent communicates over HTTP to an LLM. Trooper can observe it."



The fallback is a feature. Observability is the product.



Your agent was always talking. Now you can hear it.









Get Started






git clone https://github.com/shouvik12/trooper
cd trooper
export CLAUDE_API_KEY=sk-ant-...
go run .






Open http://localhost:3000/dashboard in your browser.



Point your agent at Trooper:




export ANTHROPIC_BASE_URL=http://localhost:3000






That's it. Zero dependencies. Pure Go. Runs in under 60 seconds.



GitHub: github.com/shouvik12/trooper






Tags: llm, agents, observability, ollama, go, opensource

CTI Threat Relationship Graph2 Knoten / 1 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - I Added a Live Dashboard to My LLM Proxy. Zero Instrumentation. Just a URL Change.
id: 8315acdb-bda3-4a5d-8b33-f2a469277264
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "I Added a Live Dashboard to My" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich I Added a Live Dashboard to My LLM Proxy.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten I Added a Live Dashboard to My LLM Proxy. Zero Instrumentation. Just a URL Change.

Thematisch verwandte Begriffe: Added, Live, Dashboard, Proxy · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-96676 | A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impa…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick