Skip to main content
Watch: I Asked Claude to Build Me a Business

AI SECURITY

27 items

27 posts

Blog
AI Agent Containment Needs a Capability Ledger

Anthropic's Claude containment writeup points to the next security layer for coding agents: deterministic capability ledgers, not another approval prompt.

Blog
Spreadsheet Agents Need Permission Ledgers

The ChatGPT for Google Sheets exfiltration report is not just a spreadsheet bug. It is a warning about agentic office tools: permissions need to be action-scoped, logged, revocable, and visible.

Blog
The Agent Security Checklist I Use Before Connecting Tools

Before an AI agent gets tools, files, APIs, MCP servers, or deployment access, decide what it can read, write, call, log, and roll back.

Blog
Permissions, Logs, and Rollback for AI Coding Agents

AI coding agents become safer when permissions, logs, and rollback are designed as one system. Here is the operating loop I would put around any agent that can edit code, run tools, or open pull requests.

Blog
Prompt Injection in Agent Apps: The Practical Version

Prompt injection stops being an abstract LLM risk once an agent can call tools. The practical defense is data boundaries, structured handoffs, tool guardrails, and approval gates around side effects.

Blog
AI Security Scanners Move the Bottleneck to Triage

Anthropic's Project Glasswing update is a useful signal for developer teams: AI can find vulnerability candidates faster than humans can verify, disclose, patch, and ship them.

Blog
Open Source Has a Bot Problem: Prompt Injection in Contributing.md

AI coding agents now read repository docs, config, issues, and comments before opening pull requests. That turns CONTRIBUTING.md and AGENTS.md into part of the security boundary.

PreviousPage 2 of 2
AI Development Stack

Get Smarter About AI Dev

New tutorials, open-source projects, and deep dives on coding agents - delivered weekly.

One email per weekReal code, not theoryFree forever