Guidance
Research and guidance.
Original studies on what agents actually do under pressure, plus open, practical guidance on every threat vector — the news and the playbook for defending autonomous systems, in one place.
01 / Research
○ In progress
Upcoming
Tool & MCP supply-chain exposure
Measuring the attack surface introduced when agents connect third-party tools and MCP servers — and which controls actually contain it.
○ In progress
Upcoming
Excessive agency and blast radius
Quantifying how over-broad tool permissions turn a single mistake into a large incident, across common agent frameworks.
02 / Guides & articles
Coming in this series
Tool and MCP supply chain: trusting code you did not write
Every tool and MCP server you connect is code running with your agent’s authority. The supply chain just got a new, under-governed front door.
Excessive agency: when an agent can do far more than the task needs
Over-broad tools and standing permissions turn a small mistake into a large incident. Least privilege is a runtime problem now.
Memory poisoning: corrupting what the agent believes is true
Persistent memory is an attack surface. Poison it once and the agent carries the attacker’s instruction into every future session.
Multi-agent cascade: one compromised agent, many actors
When agents call agents, a single injection can propagate. Trust boundaries between autonomous actors are the new perimeter.
Non-human identity: the credential problem nobody is governing
Every agent is a new identity with standing access and no joiner-mover-leaver process. Identity governance has to catch up.
The newsletter
One brief.
Every week.
News, new attacks, and practical guidance for defending AI agents — written for security leaders and the engineers shipping them. Free, and the first three chapters of Agentic AI Security (draft) land in your inbox when you confirm your email.
- First 3 chapters of the book, free
- New threats & incidents
- Defensive patterns & checklists
- Tooling and research worth your time