This blog documents, in public, what it takes to ship AI systems that don't betray the people relying on them, with a narrow and deliberate focus: agentic systems, prompt injection, MCP and tool-use security, and OAuth for the LLM era.

Posts favor concrete trade-offs and reproducible findings over threat-of-the-week commentary. Expect research write-ups with runnable code, infrastructure deep-dives on what I'd change in hindsight, and field notes from running real defenses against real attacks.

Use the category filter below to narrow in on a specific thread, or browse chronologically for the full arc — new writing lands every few weeks, and you can subscribe at the bottom of the page instead of tracking the RSS feed.