Building security infrastructure for AI agent work

I’m Gustavo Aragón, founder of Oktsec. I build products and open source infrastructure for agents working across code, tools, credentials and software supply chains. Reported vulnerabilities shape what we ship.

250+FINDINGS REPORTED
GoogleMicrosoftStripeCloudflareAWSMercury

The systems I work on.

Identity, delegated permissions, tool execution, package provenance and the infrastructure paths that connect them.

01

Agent security

How agents are attacked through their own tools, MCP servers, delegated authority and credentials.

02

Vulnerability research

Confirmed findings across agent tooling, developer CLIs, packages and cloud infrastructure.

03

Security infrastructure

Runtime governance, verifiable evidence and open source controls built for the agent ecosystem.

Reported vulnerabilities, not hypothetical risks.

Confirmed issues across agent tooling, developer CLIs, packages, OAuth providers and cloud infrastructure.

250+FINDINGS REPORTED

VRP / MSRC / HackerOne / direct disclosure

VRP · AGENT TOOLING

Reports across A2A and gemini-cli, plus a confirmed remote-code-execution path in ax.

Products and tools I’m building.

Products and open source tools for controlling authority, execution and evidence in agent systems.

Technical notes, with sources.

Notes on protocols, vulnerabilities and product decisions, with links to the underlying sources.

THE COMPLETE RESEARCH LOG 16 ESSAYS

02

JadePuffer and the first agentic ransomware

Sysdig documented what it assesses as the first agentic ransomware operation. The exploit chain was familiar; the adaptive loop and compressed response window were not.

03

Autonomy is a security boundary

Production agents usually operate with approval, supervision or guardrails. Each step away from the human changes the requirements for identity, policy, evidence and recovery.

04

MCP 2026-07-28 moves the security boundary to the server

The release candidate removes protocol sessions and makes requests easier to scale. It also leaves state integrity, authorization and resource controls squarely in each implementation.

05

The agent identity crisis, four months later

A2A v1.0 formalized signed Agent Cards, MCP stabilized Enterprise-Managed Authorization, and research prototypes explored task-scoped tokens. A status check on what is available, proposed, and still missing.

06

Joining the first cohort of Agentic AI Foundation ambassadors

The Linux Foundation initiative put MCP under open governance and opened its first ambassador program. What that means for agent infrastructure and security.

07

Working with AI agents doesn’t remove the mental load, it transforms it

The real challenge is not the model of the week, but how we manage energy and time in a reality that never rests.

08

No AI sovereignty without infrastructure sovereignty

From Atoms for Peace to frontier-model export controls: why AI sovereignty is decided in infrastructure, not model access.

09

MCP is making request identity explicit

MCP is moving authorization context from the connection to each request. The direction is clear; the stateless 2026-07-28 specification is still a release candidate.

10

Skills over MCP: who checks the manual?

SEP-2640 proposes discovering skills through MCP resources. The mechanics are promising; provenance, pinning, review, and instruction precedence remain open trust questions.

11

MCP as a supply chain: trust boundaries in agent tooling

Every server an agent calls is an implicit trust decision. How to make that decision explicit and find the remaining blind spots.

12

AgentPay: what we built at the Anthropic × Kaszek hackathon

A prototype that puts deterministic security checks in front of the payments an AI agent tries to execute.

13

Policy before agent execution: what security has to control

Static scanning stops at deploy. What it takes to constrain agent behavior in production.

14

Security is a product decision, not a checklist

The most consequential call a technical founder makes is what not to ship. Agent security cannot wait for an incident.

15

AI agents don’t have identities, and that’s a security crisis

The AI-agent identity gap, the delegation problem, and the five layers it takes to close it.

16

What public agent tooling reveals about ecosystem trust

Findings from monitoring the agent ecosystem across major registries: permissions, provenance, and drift.

Roles, recognition and research access.

Ecosystem roles

  • Claude Partner NetworkAnthropic
  • AAIF AmbassadorLinux Foundation

Professional credential

Anthropic validation for leading Claude Code implementations in organizations, from scoping and architecture through deployment, security, governance and adoption.

Recognition

  • 1st placeAnthropic × Kaszek hackathon
  • #1 Top Writer in CybersecurityHackerNoon
  • #2 Top Writer in CybersecurityHackerNoon

Research access

Gustavo Aragón has been approved for individual access to OpenAI Daybreak Blue for authorized defensive security research. This access supports his research and development work on Oktsec.

Security has always shaped the work.

Cybersecurity was one of the first disciplines I worked in. I later expanded into product, fintech and regulated infrastructure without leaving security behind. Today those paths converge in Oktsec.

Gustavo Aragón · Founder, Oktsec · Buenos Aires

CONTACT

Tell me what you’re building.

Reach out about Oktsec, AI agent security, technical assessments, advisory or talks. I work with a small number of teams where the problem is concrete and the work can be useful.

OR EMAIL DIRECTLYgus@oktsec.com

I only use this information to reply. No lists, no sharing.