IronClaw feels like a very practical answer to one of the biggest risks with AI agents: giving them real credentials. I like the approach of keeping secrets in an encrypted vault inside a TEE, injecting them only at the network boundary, and sandboxing tools with Wasm. That is a much stronger model than simply trusting the agent not to leak keys through prompt injection or malicious skills.