Blog

Security writing for people who ship

Clear, practical pieces on application and AI-agent security — the kind of thing we wish existed when we were setting this up ourselves.

$ ls blog/
✓ mcp-server-security 10 min
✓ secrets-in-git-history 5 min
✓ ai-code-review-fewer-false-positives 6 min
✓ securing-ai-agent-setups 8 min
✓ what-is-prompt-injection 7 min
$ 
·6 min read

Why AI triage cuts security-scanner false positives

Security scanners are thorough and noisy. How an LLM review pass on top of proven scanners keeps coverage while surfacing the findings that matter.

SASTcode reviewfalse positives
·8 min read

A checklist for securing your AI agent setup

Agents, skills, memory, and MCP servers each add attack surface. A practical, defensive checklist for reviewing an LLM-agent setup in a code repository.

AI securityagentsMCPchecklist
·7 min read

Prompt injection, explained for engineers

What prompt injection is, why it differs from SQL injection, and the practical patterns that keep untrusted input from hijacking your LLM agents.

AI securityprompt injectionagents