The confused deputy is back. This time, it has tools.
Why agentic systems collapse trust boundaries—and a practical framework for constraining tool use under hostile context.
↗RESEARCH ARCHIVE
Editorial field notes on software, AI, and security. These educational articles are separate from validated vulnerability advisories.
Why agentic systems collapse trust boundaries—and a practical framework for constraining tool use under hostile context.
↗Moving from static benchmark scores to security signals you can actually operate.
↗A threat model for retrieval systems that assumes every document is adversarial.
↗A faster way to find the dangerous edges of an AI agent before writing attack scenarios.
↗Why confirmation dialogs fail—and how to bind human intent to the action an agent actually takes.
↗A compact structure for turning surprising model behavior into an engineering decision.
↗