Your AI Agent Will Run Code From Strangers
Most developers don't realize their agent has zero safety checks. Here is what happens when you give an LLM permission to install tools, and what you can do about it.
Read more →Thoughts on agent security, static analysis, and building trust in autonomous systems.
Most developers don't realize their agent has zero safety checks. Here is what happens when you give an LLM permission to install tools, and what you can do about it.
Read more →A step-by-step tutorial on hooking up Agent Skill Audit to your agent via MCP, complete with examples of blocked malware.
Read more →A deep dive into the real patterns found in the wild: from prompt injections hidden in markdown to exfiltration payloads disguised as helpful scripts.
Read more →The directory is growing. Understanding how public caching helps the community, and when you should absolutely keep your audits private.
Read more →An honest look at where static analysis fits compared to manual review, sandboxed execution, and publisher allowlists.
Read more →