Agents inherit the risk of everything they install and trust.

Packages, lockfiles, install scripts, skills, CLIs and MCP servers all shape an agent’s behavior. I work on provenance, change detection and deterministic checks before execution.

The boundary I am trying to make explicit.

01

Who published the dependency?

02

Did its content change after approval?

03

What can run during installation or tool use?

Aguara applies these ideas to packages, skills, tools and MCP configurations.

VIEW THE WORK

Notes from this research thread.

Skills over MCP: who checks the manual?

SEP-2640 proposes discovering skills through MCP resources. The mechanics are promising; provenance, pinning, review, and instruction precedence remain open trust questions.

MCP as a supply chain: trust boundaries in agent tooling

Every server an agent calls is an implicit trust decision. How to make that decision explicit and find the remaining blind spots.

What public agent tooling reveals about ecosystem trust

Findings from monitoring the agent ecosystem across major registries: permissions, provenance, and drift.

CONTACT

Tell me what you’re building.

Reach out about Oktsec, AI agent security, technical assessments, advisory or talks. I work with a small number of teams where the problem is concrete and the work can be useful.

OR EMAIL DIRECTLYgus@oktsec.com

I only use this information to reply. No lists, no sharing.