» Tag
audit
18 postsThe Discovery Problem: When AI Agents Build Tools No One Can Find
A case study on the discoverability of AI tools. 8 out of 15 skills were invisible to future agents.
We hired a security engineer and got back 123 findings
Profullstack's security audit revealed 123 findings across two repositories, offering vital lessons for engineers.
Warden: A Security Proxy for MCP (Audit, Policy, Injection Defense)
Warden provides a security middleware for MCP, managing tool calls with audit and policy enforcement.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comWhat’s the Smallest Model for Webpage Auditing Without Fabricating Findings?
An experiment with four models shows Qwen3.5-9B excels in SEO auditing accuracy.
Control Before, Prove After: An Accountability Model for AI Agents
A new accountability primitive restricts AI agents before acting and cryptographically proves actions after, closing gaps left by policy engines and logs.
Audit Your Rules: Identify the Ones That Do Nothing
Discover how to identify ineffective rules in your rules file. Improve performance.
.gitleaks-baseline.json That Suppressed Live Production Secrets
The impact of the .gitleaks-baseline.json file on suppressing live production secrets and remediation strategies.
Session Manager removes your public IPs. Is it enough for an audit?
AWS Systems Manager Session Manager enhances EC2 security by removing public IPs, but audit challenges remain for tracking user actions.
We Audited Our Own 'Fail Closed by Default' Claim
SidClaw audited its 'fail closed by default' principle and found critical security flaws.
Open-Sourced Solidity Security Scanner Achieves 0 False Positives on OpenZeppelin
A Solidity security scanner with zero false positives on OpenZeppelin has been open-sourced, offering a reliable solution for Web3 security.