AI agent security research.

I study failures in agent identity, tool execution and dependency trust. The findings become controls for products and open source infrastructure.

Three research areas.

250+

Field evidence, not speculative risk.

Reported findings across formal disclosure programs keep the research tied to code, execution paths and confirmed boundaries.

Technical notes, with sources.

Notes on protocols, vulnerabilities and product decisions, with links to the underlying sources.

THE COMPLETE RESEARCH LOG 15 ESSAYS

02

Autonomy is a security boundary

Production agents usually operate with approval, supervision or guardrails. Each step away from the human changes the requirements for identity, policy, evidence and recovery.

03

MCP 2026-07-28 moves the security boundary to the server

The release candidate removes protocol sessions and makes requests easier to scale. It also leaves state integrity, authorization and resource controls squarely in each implementation.

04

The agent identity crisis, four months later

A2A v1.0 formalized signed Agent Cards, MCP stabilized Enterprise-Managed Authorization, and research prototypes explored task-scoped tokens. A status check on what is available, proposed, and still missing.

05

Joining the first cohort of Agentic AI Foundation ambassadors

The Linux Foundation initiative put MCP under open governance and opened its first ambassador program. What that means for agent infrastructure and security.

06

Working with AI agents doesn’t remove the mental load, it transforms it

The real challenge is not the model of the week, but how we manage energy and time in a reality that never rests.

07

No AI sovereignty without infrastructure sovereignty

From Atoms for Peace to frontier-model export controls: why AI sovereignty is decided in infrastructure, not model access.

08

MCP is making request identity explicit

MCP is moving authorization context from the connection to each request. The direction is clear; the stateless 2026-07-28 specification is still a release candidate.

09

Skills over MCP: who checks the manual?

SEP-2640 proposes discovering skills through MCP resources. The mechanics are promising; provenance, pinning, review, and instruction precedence remain open trust questions.

10

MCP as a supply chain: trust boundaries in agent tooling

Every server an agent calls is an implicit trust decision. How to make that decision explicit and find the remaining blind spots.

11

AgentPay: what we built at the Anthropic × Kaszek hackathon

A prototype that puts deterministic security checks in front of the payments an AI agent tries to execute.

12

Policy before agent execution: what security has to control

Static scanning stops at deploy. What it takes to constrain agent behavior in production.

13

Security is a product decision, not a checklist

The most consequential call a technical founder makes is what not to ship. Agent security cannot wait for an incident.

14

AI agents don’t have identities, and that’s a security crisis

The AI-agent identity gap, the delegation problem, and the five layers it takes to close it.

15

What public agent tooling reveals about ecosystem trust

Findings from monitoring the agent ecosystem across major registries: permissions, provenance, and drift.