Skip to main content

Blog

Page 19 of 59

All Articles

Insights on AI, machine learning, and technology strategy

Glowing yellow warning tokens move through a cool-toned review ledger sculpture toward accept, block, and retire paths, with no text or logos.
Industry Insights·

Warnings are not confetti: build a warning budget before agents merge

Eight reviewer agents approved the merge and left a page full of yellow triangles. The button is live. The warnings are still alive. Here is the artifact for that gap.

8 min read
A sealed glass vault releasing colored shards that form a mosaic trail, showing how research-agent queries can reveal private context.
Industry Insights·

Your research agent leaks through the questions it asks

Companies watch what their agents read and write. A new benchmark says watch what they ask, too. The search trail is a data surface.

7 min read
A sealed skill package on a clean workbench passing under a blue and cyan scanning beam before a gate, with a separate violet-lit agent work area glowing on the far side, in a cool navy, cyan, and violet palette.
Industry Insights·

Scan the skill before the agent reads it

A new static scanner called SkillsGuard treats agent skill packages as untrusted code, not documentation. The idea worth keeping: a skill is a future instruction source, so put it on a quarantine bench before it loads.

9 min read
A cool-toned glass audit chain with glowing action capsules, a fault pulse, and a blank tamper-test cube on a dark navy background.
Industry Insights·

Your agent audit log needs a rehearsal, not a promise

RootSign shows why agent audit logs need rehearsal. The chain may verify cleanly, but concurrency, retries, redaction, and tamper tests still deserve a deliberate break-it-first run.

6 min read
A dark studio holding a blank glass cube, thin glowing evidence threads entering it from one side, a small blank red glass barrier just outside the cube, and a sealed vault shape behind it, in a navy, cyan, emerald, and violet palette with no text.
Industry Insights·

Don't ask an AI if you're audit-ready. Put it in a read-only room.

A small open-source project turns a coding agent into a read-only compliance auditor. The reusable idea isn't the prompt. It's the room you run it in.

9 min read
A central glass prism switchboard routes glowing request paths between blank agent nodes in a cool navy, cyan, emerald, and violet palette.
Industry Insights·

Your agent stack needs a switchboard, not another brain

The hard part of multi-agent work is not picking a framework. It is the traffic between agents after one request fans out. Here is a copyable ledger for watching it.

9 min read
A clean dependency report sits beside a separate glowing inspection lane for MCP servers, plugins, skills, and hooks before runtime approval.
Industry Insights·

Your SBOM stops before the agent starts

A clean npm audit does not mean a clean workstation. MCP servers, plugins, and skills can sit outside the review. The Agent BOM intake note catches them.

9 min read
Abstract courier path where a request token enters a glowing local vault and only a result returns, the raw key never leaving the core.
AI Development·

Give the agent a ticket, not the key

When an AI agent needs Stripe access, the default move hands it the raw key. A better pattern gives it a secret handle, a host allowlist, and a daemon that owns the call. Here is the courier policy that makes that concrete.

9 min read
A browser agent reaches local loopback surfaces only through authentication, allowed-caller, isolation, and kill-switch gates recorded in a loopback exception register.
Industry Insights·

Localhost is not a sandbox when the agent can browse

AutoJack turned a single web page into a host-level code execution path through a local agent control socket. The useful lesson is not panic about one pre-release bug. It is that loopback stops being private when a browsing agent shares a host with privileged local services.

6 min read
Cool-toned studio scene of blank layered footer tags trailing a single commit strip, with no readable text.
AI Development·

The AI contribution label belongs in the commit, not the meeting notes

You run git log and the last line of the commit reads Co-authored-by: Claude. It shows up in the contributors list like a teammate who just joined. It isn't one. That gap is the whole post.

7 min read
Cool-toned studio scene with a small agent orb sending a narrow light path through a glass gate into a cloud-filled deployment cube, with a separate claim pedestal nearby.
Industry Insights·

Give the agent a boarding pass, not a badge

A background coding agent finishes a Worker and hits a sign-in wall. The risky fix is a permanent login. Cloudflare's temporary accounts point at a narrower one: disposable authority plus a claim ticket with a deadline.

7 min read
Cool-toned glass specimen tray with glowing abstract agent objects sorted into compartments before reaching blank control blocks.
Industry Insights·

You can't govern an agent you can't name

A company cannot protect a swarm it has not counted. NeuralTrust's $20M raise is a signal that agent security is becoming infrastructure, but the first useful artifact is still a roster.

7 min read