Skip to main content

Blog

Security notes for AI-assisted development.

Practical guides on prompt injection, MCP risk, agent permissions, approvals, and action logs.

Latest guides

MCP security11 min read

MCP security risks for Claude Code users

An MCP server extends what Claude Code can reach. Review identity, scopes, commands, network access, and approval behavior before connecting it.

AI agent security12 min read

AI Agent Permission Policies That Actually Work

Replace “the agent has tools” with explicit allow, block, and approval rules that check identity, action, target, environment, and impact before execution.