Research

Notes from the security frontier.

Practical research on governing AI systems, securing agent tools, and investigating failures without theatrics.

Featured

MCP Security

·6 min read

What is ASI04 MCP Tool Poisoning?

Tool descriptions are model-readable text — which makes them an instruction channel. How a poisoned catalog turns a helpful agent into an exfiltration engine, and how to detect it before registration.

Read note

All research

·7 min

Building a Self-Improving Security Model

Static classifiers decay the day they ship. Inside the nightly loop that generates attacks, captures misses, retrains, and refuses to deploy anything that regresses.

Read note
·8 min

OWASP Agentic AI Top 10, Explained

Agents do not just talk — they act. A walkthrough of ASI01 through ASI10, what each risk looks like in production, and the control that contains it.

Read note