The current state of security for autonomous agents in the cloud
Security controls and best practices for architecting the runtime: isolation, identity, egress, credentials, and a tool broker outside the model.

Search for a command to run...
Articles tagged with #security
Security controls and best practices for architecting the runtime: isolation, identity, egress, credentials, and a tool broker outside the model.

I was working on a new app and came across Matt Pocock's /grill-with-docs skill that works as a structured interrogation tool that stress-tests your plan against your project's domain model, cross-ref

Building a normalised finding schema across six scanners and an MCP layer that lets developers, security engineers, and CI pipelines query, fix, and verify vulnerabilities, all from the tools they already have open.

Why the assumption that CI/CD is a trusted internal tool has already cost organisations dearly

Part 1 - Lab setup, attacker simulation, and finding exploitable misconfigurations

Securing AI: Microsoft Shares Key Research Findings
