Latest / AI Agent Security
How to Read the Scope of an AI Agent Security Assessment
A client review method for connecting an AI agent assessment to the permissions and release decision it actually covers.
Read latestInsights
Analysis of AI-security threats, autonomous-agent risk, and the techniques attackers actually use, published through KevinBytes.
Latest / AI Agent Security
A client review method for connecting an AI agent assessment to the permissions and release decision it actually covers.
Read latestField guide
A visual guide to the 2025 OWASP categories for AI agents, RAG, MCP, and tool-connected applications.
Open the OWASP guidePractical resources
Archive
Showing 40 of 40 posts.
A client review method for connecting an AI agent assessment to the permissions and release decision it actually covers.
A practical review package for agent memory write authority, provenance, tenant isolation, deletion and pilot release decisions.
An action-centered audit trail for agent proposals, approval, dispatch, downstream effects, denials and missing telemetry.
A worked acceptance plan for agent access controls, with meaningful deny cases, failure behavior and explicit release decisions.
A review dossier for laboratory assistants that separates analysis, proposed changes, operator authority and physical system effects.
Define customer authorization, delegated roles, identity coverage, telemetry custody and acceptance criteria for a scoped MSP security review.
A practical enterprise framework for deciding whether an AI agent should proceed, enter a limited pilot, or remain out of production.
How enterprise teams can let AI agents use real tools without letting the model authorize, approve, or execute high-impact actions unchecked.
How to review overlapping controls around a support agent, map owners and coverage, and prepare a tested rollback before retiring a tool.
A practical preparation guide with a bounded agenda, synthetic permissions and retrieval exercises, participant roles, and useful workshop outputs.
A practical decision guide to 17 web discovery, access, authentication, tool, and commerce mechanisms for AI agents.
How to publish typed HTTP links for real machine resources without turning performance hints into false service discovery.
A maturity and security review of the DNS-AID draft, SVCB records, DNSSEC, and the decision not to advertise a nonexistent agent endpoint.
How Cloudflare Markdown for Agents handles Accept, Vary, token counts, origin policy headers, conversion limits, and rollback.
How RFC 9309 group matching affects AI crawler policy, protected paths, operator tokens, and post-access content-use declarations.
What Web Bot Auth asks bot operators to publish and sign, how verification works, and why content origins should not add fake key directories.
How Content Signals declares ai-train, search, and ai-input preferences, and why origin policy should remain authoritative.
How RFC 9727 discovers maintained public APIs through a well-known URI, Linkset JSON, typed relations, and explicit ownership.
How agents distinguish OAuth authorization-server metadata from OpenID Provider configuration and reject invented issuers or endpoints.
How RFC 9728 binds a protected resource to authorization servers, scopes, token methods, and OAuth discovery used by MCP clients.
A technical review of WorkOS's open auth.md proposal, its OAuth building blocks, and why structured metadata must remain authoritative.
What current draft SEP-2127 proposes for MCP Server Cards, catalog discovery, runtime checks, and stale metadata risk.
How Cloudflare's Agent Skills v0.2.0 proposal discovers skill packages, verifies SHA-256 digests, and preserves package trust boundaries.
How current WebMCP draft APIs register browser tools, use Permissions Policy, preserve human oversight, and replace obsolete context calls.
How x402 uses HTTP 402 and signed payment headers, what facilitators do, and why a site needs a priced machine resource before adoption.
How MPP uses the Payment HTTP authentication scheme, OpenAPI pricing metadata, charge and session intents, and server fulfillment controls.
How UCP business profiles describe services, capabilities, payment handlers, transport bindings, signed requests, and merchant responsibility.
How ACP connects product feeds, merchant checkout state, delegated payment tokens, idempotency, and order fulfillment without displacing the seller.
Agents that can change deployment state, repository permissions or production configuration need the controls applied to privileged automation.
A pre-launch review list for AI agents that touch production APIs, customer data, tools, memory, or RAG context.
A security checklist for MCP servers, clients, OAuth flows, tokens, tools, permissions, trust boundaries, logging, and blast radius.
AI agent blast radius is the maximum plausible damage an agent can cause if manipulated, misconfigured, over-permissioned, or exposed to hostile context.
How to review RAG systems for authorization failures, tenant-isolation gaps, prompt injection, vector-store leakage, document poisoning, and audit logging.
How founders, CTOs, CISOs, and product-security teams can choose between an AI red team, LLM pentest, AI security assessment, or production readiness review.
How engineering and product teams can prepare AI agents for enterprise security review, production launch, customer diligence, and governance scrutiny.
An MCP threat model for teams connecting LLMs and AI agents to tools, OAuth tokens, APIs, local servers, SaaS systems, and production workflows.
How indirect prompt injection reaches AI agents through RAG systems, copilots, MCP tools, webpages, emails, PDFs, memory, and tool outputs.
A framework for classifying AI agent tool permissions by business impact, authorization boundary, required controls, and production readiness.
Common RAG authorization failures, tenant-isolation gaps, vector-store access-control mistakes, source attribution issues, and safer retrieval design.
How disciplined engineering assessment helps legal, insurance, and executive teams understand root cause, technical exposure, and the next defensible decision...