» Tag
security
437 postsThe Agent Security Stack: Transport, Identity, Policy, Runtime
The agent security stack addresses transport, identity, and policy layers, providing crucial insights for engineers.
PromptFiction Flaw: Auto-Submitted Hidden Prompts in Claude Desktop
Oasis Security's research uncovered the PromptFiction flaw in Claude Desktop, enabling commands to be executed without user approval.
FastAPI Agent Template: Task Ownership Must Cross Every Layer for Production
Vercel's FastAPI template for OpenAI Agents SDK emphasizes the importance of cross-layer task ownership for production readiness.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comThe Advisory Said It Was Fixed. I Didn't Believe It Until I Broke It Myself.
An engineer tested the CVE-2026-39973 vulnerability in apktool, emphasizing the importance of real testing over mere advisories.
corpus-scrub 0.1.0: Detects and Redacts PII and Secrets in Training Data
corpus-scrub 0.1.0 cleans training data by detecting and redacting PII and secrets.
E2EE Notes with Passkey as Encryption Key on Workers + D1
Explore the use of passkeys as encryption keys in E2EE applications with the pknotes project.
MonkeyCode Human Review: What Evidence Should Make Approval Possible?
Proposed human review framework for MonkeyCode SaaS. Key evidence and stop conditions for the approval process are discussed.
Agentmetry – An Open-Source Flight Recorder for AI Agents
Agentmetry offers an open-source flight recorder and security layer for AI agents.
My MCP Server Only Talks to Trusted APIs, But Is the Data Reliable?
MCP server security isn't enough; the reliability of returned data must be questioned.
Exploiting LLM Vulnerabilities: Accessing Dangerous Instructions
Dave Kuszmar revealed vulnerabilities in LLMs that allowed access to dangerous instructions, indicating a critical security issue across the industry.