Security for agents that act on real systems.

AI agents read files, call tools, use credentials and trigger actions. I research the identity, authorization and execution controls required before that work can scale safely.

The boundary I am trying to make explicit.

01

Which agent instance is acting?

02

What authority was delegated for this task?

03

What evidence proves what happened?

This research informs runtime policy and verified evidence in Oktsec.

VIEW THE WORK

Notes from this research thread.

JadePuffer and the first agentic ransomware

Sysdig documented what it assesses as the first agentic ransomware operation. The exploit chain was familiar; the adaptive loop and compressed response window were not.

Autonomy is a security boundary

Production agents usually operate with approval, supervision or guardrails. Each step away from the human changes the requirements for identity, policy, evidence and recovery.

MCP 2026-07-28 moves the security boundary to the server

The release candidate removes protocol sessions and makes requests easier to scale. It also leaves state integrity, authorization and resource controls squarely in each implementation.

The agent identity crisis, four months later

A2A v1.0 formalized signed Agent Cards, MCP stabilized Enterprise-Managed Authorization, and research prototypes explored task-scoped tokens. A status check on what is available, proposed, and still missing.

AgentPay: what we built at the Anthropic × Kaszek hackathon

A prototype that puts deterministic security checks in front of the payments an AI agent tries to execute.

Policy before agent execution: what security has to control

Static scanning stops at deploy. What it takes to constrain agent behavior in production.

AI agents don’t have identities, and that’s a security crisis

The AI-agent identity gap, the delegation problem, and the five layers it takes to close it.

CONTACT

Tell me what you’re building.

Reach out about Oktsec, AI agent security, technical assessments, advisory or talks. I work with a small number of teams where the problem is concrete and the work can be useful.

OR EMAIL DIRECTLYgus@oktsec.com

I only use this information to reply. No lists, no sharing.