Writing
Turning agent security notes into practical posts with examples that avoid publishing working abuse payloads.
The latest published /now entry, preserved as the journal evolves.
Turning agent security notes into practical posts with examples that avoid publishing working abuse payloads.
Sketching eval harness patterns that can catch model regressions without leaking the private adversarial corpus.
Designing small trust gates around tool output, retrieval results, and generated actions.
Prompt injection research, browser-agent failure modes, and practical isolation designs for tool-using models.
Upcoming notes: quarantined LLM architecture, schema rejection ergonomics, and how to review tool calls without turning every workflow into a modal storm.