Skip to content
Back to Blog
Blog series
10 posts · 106 min read

Agent security engineering series

Threat-model, contain, authorize, and red-team tool-using agents with deterministic controls around the model.

Share:XBSMRedditHNEmail
1
August 24, 2026·11 min read

HarnessRisk in Practice: Turn the Agent Lifecycle Into a Security Test Matrix

A deep implementation guide to lifecycle security testing for agent harnesses: configuration, extensions, runtime, persistence, actions, recovery, evidence oracles, and release gates.

2
Persistent Memory Poisoning: The Attack That Outlives the Session illustration
August 12, 2026·16 min read

Persistent Memory Poisoning: The Attack That Outlives the Session

A production security architecture for attributable, revalidated, authority-bounded, traceable, and selectively reversible agent memory.

3
The AI Agent Access Graph: What CISOs Need to See illustration
July 19, 2026·14 min read

The AI Agent Access Graph: What CISOs Need to See

AI agents compose identities, tools, data, and delegated authority. Build the access graph, drift alerts, and revocation controls your CISO needs.

4
Threat-Model an AI Agent: Sources, Sinks, Authority, and Blast Radius illustration
July 12, 2026·9 min read

Threat-Model an AI Agent: Sources, Sinks, Authority, and Blast Radius

A practical AI agent threat-modeling method that maps untrusted sources to dangerous sinks, then constrains identity, authority, data, and blast radius at deterministic runtime boundaries.

5
Prompt Injection Is a Boundary Problem, Not a Prompt Problem illustration
February 21, 2026·9 min read

Prompt Injection Is a Boundary Problem, Not a Prompt Problem

Why "smarter prompts" don't defend against indirect prompt injection, and what changes when authority lives outside the model's view.

6
Agent Identity Is the New Trust Boundary illustration
May 17, 2026·13 min read

Agent Identity Is the New Trust Boundary

A practical model for separating agent identity, workload proof, user delegation, scoped authority, and audit across MCP and A2A.

7
Secure the MCP and Tool Supply Chain: Trust Must Be Continuous illustration
July 12, 2026·15 min read

Secure the MCP and Tool Supply Chain: Trust Must Be Continuous

MCP tool descriptions enter the agent's decision loop. Use this attack trace, control scorecard, and policy to stop metadata from becoming authority.

8
Build the Tool Gateway: The Boundary That Actually Stops a Bad Action illustration
May 5, 2026·5 min read

Build the Tool Gateway: The Boundary That Actually Stops a Bad Action

A build-along for the Tool Gateway: adapter manifests, typed envelopes, resolver checks, dispatch, and destructive-action boundaries.

9
Approval Gates in Code: The Destructive-Mode Handshake illustration
May 6, 2026·5 min read

Approval Gates in Code: The Destructive-Mode Handshake

A build-along for approval gates: frozen evidence, human signatures, gateway redemption, and replayable destructive-action handshakes.

10
Red-Team Agent Hijacking: Build a Security Eval Gate for Repeat Attacks illustration
July 12, 2026·9 min read

Red-Team Agent Hijacking: Build a Security Eval Gate for Repeat Attacks

A practical agent-hijacking evaluation harness: scenario design, adaptive and repeated attempts, path-aware metrics, deterministic release gates, and production replay.