» Tag
authorization
7 postsStatic Scanner Finds 30 Unguarded Destructive Actions in AI Agent Frameworks
An open-source scanner analyzed 25 AI agent frameworks and confirmed 30 cases where models can delete data, deploy, or send webhooks unauthorized.
APC Framework Closes Authorization Gaps in Multi-Agent LLM Systems
A new authorization framework, APC, tracks delegated authority to block prompt-injection and unsafe action combinations in AI agents.
Engineering Production Agentic Systems, Part 2: Guardrails
Part 2 of a field manual on production agentic systems: tool surface design, authorization scopes, and audit-trail engineering explained.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comWhy AI Agents Must Never Choose Their Own Acting Subject
AI agents shouldn't self-assign identity via tool arguments. Learn why acting subjects must come from trusted boundaries, not model output.
Real-Time Risk Signals for AI Agent Authorization
How SSF, CAEP and RISC feed real-time runtime risk signals into AI agent authorization, enabling automatic session revocation on anomalies.
Threat-Model an MCP Server as a Privileged API Gateway
An MCP server acts as a secure gateway for APIs. Learn about authorization and security measures for effective implementation.
Stop Mass Assignment Before It Reaches Your Authorization Layer
Implement a three-tier authorization process to prevent mass assignment.