Stop Dangerous AI Agent Commands Before They Run
A practical command-control pattern for coding agents with shell, filesystem, network, and credential access.
Read articleAgentGuard Research
Practical guidance, independent reviews, and clear explanations for teams building AI agents that can take real action.
A practical command-control pattern for coding agents with shell, filesystem, network, and credential access.
Read articleA deployment guide for putting enforceable controls between an agent's intent and its real-world side effects.
Read articleDraw an AI agent threat model that connects attacker influence, trust boundaries, identities, controls, and observable asset changes.
Read articleTrace sensitive data from source and classification through model context, connectors, recipients, delivery, and safe audit records.
Read articleProtect RAG 2.0 across retrieval, generation, feedback, identity, context assembly, and downstream agent actions.
Read articlePair each prompt-injection prevention control with an owner, adversarial case, target-state assertion, and recovery decision.
Read articleTranslate all ten OWASP agentic AI risks into control surfaces, abuse cases, owners, tests, and retained evidence.
Read articleSecure the complete MCP request path from client identity and transport through server policy, downstream effect, and audit evidence.
Read articleGovern MCP servers and tools from catalog admission through identity, change control, runtime evidence, exceptions, and retirement.
Read articleMake Cursor workspace scope, context exposure, extensions, terminal actions, and branch outcomes separately reviewable.
Read articleConstrain Claude Code workspace access, connected tools, credentials, commands, and repository changes with reproducible checks.
Read articleBuild prompt-injection tests that follow hostile input through tool decisions and verify the downstream target stays unchanged.
Read article