TKOResearch
Menu

Insights

Research, in the open.

Analysis of AI-security threats, autonomous-agent risk, and the techniques attackers actually use, published through KevinBytes.

Field guide

OWASP LLM Top 10, mapped to real AI systems.

A visual guide to the 2025 OWASP categories for AI agents, RAG, MCP, and tool-connected applications.

Open the OWASP guide

Practical resources

Working guides for AI-security decisions.

Archive

Published research and technical guides.

Request a scoping call

Showing 30 of 30 posts.

Agent-Readable Web6 min read

robots.txt Rules for AI Crawlers

How RFC 9309 group matching affects AI crawler policy, protected paths, operator tokens, and post-access content-use declarations.

Last reviewed July 16, 2026Read guide
Agent-Readable Web5 min read

WebMCP Browser Tools for AI Agents

How current WebMCP draft APIs register browser tools, use Permissions Policy, preserve human oversight, and replace obsolete context calls.

Last reviewed July 16, 2026Read guide
Agent-Readable Web6 min read

x402 HTTP Payments for AI Agents

How x402 uses HTTP 402 and signed payment headers, what facilitators do, and why a site needs a priced machine resource before adoption.

Last reviewed July 16, 2026Read guide
Agent-Readable Web7 min read

Agentic Commerce Protocol Checkout

How ACP connects product feeds, merchant checkout state, delegated payment tokens, idempotency, and order fulfillment without displacing the seller.

Last reviewed July 16, 2026Read guide
AI Agent Security10 min read

What Is AI Agent Blast Radius?

AI agent blast radius is the maximum plausible damage an agent can cause if manipulated, misconfigured, over-permissioned, or exposed to hostile context.

Last reviewed May 4, 2026Read guide