Security
16 posts — newest first.
-
NVIDIA Moved the Agent Watchdog to a Different Chip
The Open Agent Safety Platform puts enforcement on a DPU, outside the host the agent runs on. The instinct is decades old. The shape is the question.
-
Prompt Injection: Why Your Agent Believes the Wrong Text
An LLM sees one stream of tokens, not instructions and data. That is why prompt injection has no parser fix — and why provenance, not filtering, is the control.
-
Token Exchange: Delegation Is Not Impersonation (RFC 8693)
When a service calls another service for a user, the token it carries decides whether your audit log says who acted. RFC 8693 makes that a design choice.
-
OAuth, OIDC, and JWT: Who Are You, and What Are You Allowed to Do?
Three terms people use interchangeably and shouldn't: OAuth delegates access, OIDC proves identity, JWT is the token format. Mixing them up causes real bugs.
-
Secrets Management: Scope, Lifetime, and the Blast Radius of a Leak
Storing secrets safely is the easy half. The damage is decided by what one credential can do, for how long, and whether you can revoke it safely.
-
Agent browsing got 3–7× cheaper and 1.8× slower. Both numbers change your design.
Cloudflare's Kitesurf is a browser built for agents, not people. The measured trade-off, what it can't do, and why cheap browsing rewrites your threat model.
-
OWASP published an MCP Top 10. Go count your servers before you read it.
OWASP now has a Top 10 dedicated to Model Context Protocol. The list is useful — but the census behind it is the part that should worry your platform team.
-
Identity was the easy half. Agent authorization is becoming an audit-trail problem.
NIST, a Senate bill and the MCP roadmap converge on one requirement: prove which agent did what, for whom, under whose grant. Your traces do not.
-
An agent breached Hugging Face in 4.5 days. The controls that would have stopped it are boring.
Hugging Face's July 2026 postmortem is the clearest agent-intrusion writeup we have. The failures were IMDS, admission policy, and one shared credential.
-
Your agent installs Markdown from the internet and runs it. We spent 20 years learning not to do that.
Agent skills are dependencies with none of the controls. What the 2026 research found, why scanners miss it, and seven fixes for platform teams.
-
The OWASP Agentic Top 10, translated for platform teams
OWASP's Agentic Top 10 reads like a security doc, but the mitigations are platform controls. Mapping all ten risks to infrastructure you already run.
-
Your agents need identities, not API keys
Every AI agent is a non-human identity — most run on shared, long-lived API keys no IAM review sees. Per-agent identity and your credential blast radius.
-
MCP goes stateless — what the 2026 release candidate means for your SRE tooling
The 2026-07-28 MCP release candidate deletes the session handshake for a stateless HTTP core and hardens OAuth. What changes for your agents, and when.
-
No anonymous inference endpoints — the MCP security principle you're probably violating
The NSA and NIST put MCP on notice: agents are a funnel for prompt injection and privilege abuse. Why 'no anonymous inference endpoints' — and how to comply.
-
The MCP gateway pattern: five jobs your agent runtime can't skip
Letting agents call MCP servers directly repeats the no-API-gateway mistake. The five jobs an MCP gateway must do, with reproducible patterns for each.
-
TLS and Public-Key Cryptography, Explained Without the Math
Every https and model API call rides on TLS. How public-key crypto solves key distribution, what a certificate proves, and the cert-expiry realities.