Agent security
How agents are attacked through their own tools, MCP servers, delegated authority and credentials.
I’m Gustavo Aragón, founder of Oktsec. I build products and open source infrastructure for agents working across code, tools, credentials and software supply chains. Reported vulnerabilities shape what we ship.

EXPERTISE / 01
Identity, delegated permissions, tool execution, package provenance and the infrastructure paths that connect them.
How agents are attacked through their own tools, MCP servers, delegated authority and credentials.
Confirmed findings across agent tooling, developer CLIs, packages and cloud infrastructure.
Runtime governance, verifiable evidence and open source controls built for the agent ecosystem.
FIELD RESEARCH / 02
Confirmed issues across agent tooling, developer CLIs, packages, OAuth providers and cloud infrastructure.
VRP / MSRC / HackerOne / direct disclosure
Reports across A2A and gemini-cli, plus a confirmed remote-code-execution path in ax.
PRODUCTS & OPEN SOURCE / 03
Products and open source tools for controlling authority, execution and evidence in agent systems.
The security platform for AI agent work. Define policy, govern approved execution environments and verify what agents actually did.
02An open source security engine that checks packages, lockfiles, install scripts, MCP configurations, skills and tools before trust is granted.
03A local delivery workflow for AI coding agents: scope, plan, build, review, security, QA and ship, with evidence left on disk.
04Structured security reviews for software systems, automation paths, MCP servers and agent workflows, with evidence and clear next steps.
BLOG / 04
Notes on protocols, vulnerabilities and product decisions, with links to the underlying sources.
Sysdig documented what it assesses as the first agentic ransomware operation. The exploit chain was familiar; the adaptive loop and compressed response window were not.
03Production agents usually operate with approval, supervision or guardrails. Each step away from the human changes the requirements for identity, policy, evidence and recovery.
04The release candidate removes protocol sessions and makes requests easier to scale. It also leaves state integrity, authorization and resource controls squarely in each implementation.
05A2A v1.0 formalized signed Agent Cards, MCP stabilized Enterprise-Managed Authorization, and research prototypes explored task-scoped tokens. A status check on what is available, proposed, and still missing.
06The Linux Foundation initiative put MCP under open governance and opened its first ambassador program. What that means for agent infrastructure and security.
07The real challenge is not the model of the week, but how we manage energy and time in a reality that never rests.
08From Atoms for Peace to frontier-model export controls: why AI sovereignty is decided in infrastructure, not model access.
09MCP is moving authorization context from the connection to each request. The direction is clear; the stateless 2026-07-28 specification is still a release candidate.
10SEP-2640 proposes discovering skills through MCP resources. The mechanics are promising; provenance, pinning, review, and instruction precedence remain open trust questions.
11Every server an agent calls is an implicit trust decision. How to make that decision explicit and find the remaining blind spots.
12A prototype that puts deterministic security checks in front of the payments an AI agent tries to execute.
13Static scanning stops at deploy. What it takes to constrain agent behavior in production.
14The most consequential call a technical founder makes is what not to ship. Agent security cannot wait for an incident.
15The AI-agent identity gap, the delegation problem, and the five layers it takes to close it.
16Findings from monitoring the agent ecosystem across major registries: permissions, provenance, and drift.
EXTERNAL CREDENTIALS / 05
Anthropic validation for leading Claude Code implementations in organizations, from scoping and architecture through deployment, security, governance and adoption.
Gustavo Aragón has been approved for individual access to OpenAI Daybreak Blue for authorized defensive security research. This access supports his research and development work on Oktsec.
ABOUT / 06
Cybersecurity was one of the first disciplines I worked in. I later expanded into product, fintech and regulated infrastructure without leaving security behind. Today those paths converge in Oktsec.
CONTACT
Reach out about Oktsec, AI agent security, technical assessments, advisory or talks. I work with a small number of teams where the problem is concrete and the work can be useful.
OR EMAIL DIRECTLYgus@oktsec.com