Agent Security
7 essays tagged with Agent Security.
HarnessRisk in Practice: Turn the Agent Lifecycle Into a Security Test Matrix
A deep implementation guide to lifecycle security testing for agent harnesses: configuration, extensions, runtime, persistence, actions, recovery, evidence oracles, and release gates.
Harness Engineering in August 2026: The Control Plane Gets Measured
A source-backed state of the field on harness engineering: what shipped, what the newest research measured, what practitioners are debating, and the roadmap from agent loops to proof-carrying runtimes.
DeepSeek Harness: Everything Is a Plugin—Except Trust
A source-code critique of DeepSeek Harness and Cordis: why an everything-is-a-plugin runtime matters, where reversibility stops, and why self-evolution still needs an immutable control plane.
The AI Agent Access Graph: What CISOs Need to See
AI agents compose identities, tools, data, and delegated authority. Build the access graph, drift alerts, and revocation controls your CISO needs.
Red-Team Agent Hijacking: Build a Security Eval Gate for Repeat Attacks
A practical agent-hijacking evaluation harness: scenario design, adaptive and repeated attempts, path-aware metrics, deterministic release gates, and production replay.
Threat-Model an AI Agent: Sources, Sinks, Authority, and Blast Radius
A practical AI agent threat-modeling method that maps untrusted sources to dangerous sinks, then constrains identity, authority, data, and blast radius at deterministic runtime boundaries.
Secure the MCP and Tool Supply Chain: Trust Must Be Continuous
MCP tool descriptions enter the agent's decision loop. Use this attack trace, control scorecard, and policy to stop metadata from becoming authority.