Security
7 essays tagged with Security.
Persistent Memory Poisoning: The Attack That Outlives the Session
A production security architecture for attributable, revalidated, authority-bounded, traceable, and selectively reversible agent memory.
OpenAI's Latest Work: A 10-Day Field Report
A source-backed 10-day delta across Codex, plugins, API operations, model economics, security scanning, and the GPT-5.4 migration.
Reverse Prompting: Work Backward from the Output, Then Prove the Prompt
Reverse prompting is useful when it turns a desired output into a candidate instruction contract and validates that contract forward. Here is the research, the workflow, the failure modes, and the security boundary.
Agent Identity Is the New Trust Boundary
A practical model for separating agent identity, workload proof, user delegation, scoped authority, and audit across MCP and A2A.
Agentic Incident Command Center: Agents Can Coordinate, Boundaries Still Decide
How incident-response agents can coordinate signal, diagnosis, remediation, communications, and approvals without bypassing operational boundaries.
MCP Adapters in Production: The Manifest Is the Safety Boundary
How MCP fits behind a production adapter manifest with schemas, auth, approval modes, idempotency, observability, and replay.
Prompt Injection Is a Boundary Problem, Not a Prompt Problem
Why "smarter prompts" don't defend against indirect prompt injection, and what changes when authority lives outside the model's view.