Sign in

Darinor

@darinor.com
102 followers 344 following 158 posts

Notes on building AI agents that don't leak, break, or turn into liabilities. darinor.com 🔗 AI + cyber starter pack: bsky.app/starter-pack/darinor.com/3…

PostsRepliesMedia
Darinor @darinor.com · 27/09/2026
CSP Nonces and the Same-Origin Policy Solve Different Problems www.darinor.com/blog/csp-non... #Appsec #WEBSecurity #CSP
darinor.com
CSP Nonces and the Same-Origin Policy Solve Different Problems
A CSP nonce and the same-origin policy both show up in the same sentence about XSS, but they guard different boundaries — one says which script on this page is allowed to run, the other says which ori...
021
Darinor @darinor.com · 26/09/2026
How to Build an Agent Audit Trail Before You Need It www.darinor.com/blog/how-to-... #AgenticAI #IncidentResponse #DetectionEngineering #AgentArchitecture
darinor.com
How to Build an Agent Audit Trail Before You Need It
The provider's copy expires on their clock. Build the trail you own — context snapshots, provenance, a config hash, into storage the agent can't rewrite.
021
Darinor @darinor.com · 09/09/2026
Approval is a request for the agent to be trusted. Containment is what stays true when it isn't. One lives in the model's behavior; the other lives in the environment. And only one of them survives a bad day.
131
Darinor @darinor.com · 09/09/2026
The Same-Origin Policy Is Only as Strong as Your Browser Agent www.darinor.com/blog/agentic... #AISecurity #AgenticAI #PromptInjection #Appsec
darinor.com
The Same-Origin Policy Is Only as Strong as Your Browser Agent
University of Washington researchers showed a prompt injection can turn an agentic browser's own cross-origin access against it — SOP enforcement now bottoms out at the agent's injection defenses.
010
Darinor @darinor.com · 09/09/2026
“The agent with access to find every weakness is the agent with access to exploit every weakness. Offensive capability and insider threat are the same thing wearing different labels.”
011
Darinor @darinor.com · 08/09/2026
“The difference between seeing an agent and controlling it is the difference between an inventory entry and a security architecture.”
000
Darinor @darinor.com · 08/09/2026
“Sixteen thousand servers appeared in months. Authorization is optional. STDIO transport has no authentication. The protocol's own specification treats security as someone else's problem.”
001
Darinor @darinor.com · 08/09/2026
“The fundamental shift is from testing what the model says to testing what the agent does. Output text is a risk. Executed actions are a threat.”
000
Darinor @darinor.com · 07/09/2026
“The web security model was built around the idea that a human sits between tabs and decides what crosses. Agentic browsers remove that human from the loop, and the isolation model has not caught up.”
002
Darinor @darinor.com · 07/09/2026
“Agents execute high-impact actions without clear attribution chains. The credential says human. The action was autonomous. The audit trail stops at a shared service account.”
000
Darinor @darinor.com · 07/09/2026
“The difference between seeing an agent and controlling it is the difference between an inventory entry and a security architecture.”
100
Darinor @darinor.com · 06/09/2026
Gartner, on the CTEM gap: Seventy-one percent of organizations could benefit from CTEM, and 60 percent are actively pursuing it, but the gap between intent and execution remains the core challenge. #CTEM #Security #RiskManagement
000
Darinor @darinor.com · 05/09/2026
Your Agent Is Impersonating You www.darinor.com/blog/delegat... #AgenticAI #AISecurity #WorkloadIdentity #MCP
darinor.com
Your Agent Is Impersonating You
When an agent acts with your token, every downstream log says you did it. Delegation, not impersonation: one token, two identities — and a delegation chain nobody enforces yet.
120
Darinor @darinor.com · 04/09/2026
This one keeps coming back to me: "GhostApproval is a reminder that agent security is not only about what the model decides. It is about what the tool shows the user, what the environment allows the tool to touch, and where the trust boundary really sits." #AICoding #AIAgents #Security
010
Darinor @darinor.com · 04/09/2026
A defensive agent with the power to contain a breach is a defensive agent with the power to cause one. Authority without verification is another attack surface. e.q. a containment ‘kill‑switch’ can isolate or erase systems. Mitigate with least privilege, attestations and audits. #AISecurity
010
Darinor @darinor.com · 03/09/2026
"Twenty-six percent of tool calls violated policy when safety was a prompt rather than a gate. That number is the argument for infrastructure-layer governance." #MCP #AIAgents #Governance
120
Darinor @darinor.com · 03/09/2026
Workload identity verifies an agent is genuine. Agentic identity verifies it's authorized to act e.q. roles, policies, or permissions granting the requested access. Together they enforce trust and least privilege. #CloudSecurity #Identity #Agentic
020
Darinor @darinor.com · 03/09/2026
Stealing an AI coding assistant's API key is not credential theft in the traditional sense. It is theft of a trusted actor that already has permission to act on behalf of the developer. #npm #SupplyChain #AIAgents
020
Darinor @darinor.com · 02/09/2026
Every pillar of identity management: authentication, access control, authorization, auditing, administration, and availability, must be rebuilt for entities that act in seconds, not days, and whose permissions must expire when the task does. #AIAgents #IdentitySecurity
020
Darinor @darinor.com · 02/09/2026
The agent does not need to know which button to click. It needs to know what outcome to produce and which tools are available to produce it. APIs, integrations, or human handoffs, so it can plan, adapt and execute #Automation #AIAgents
020
Darinor @darinor.com · 01/09/2026
A defensive agent with the power to contain a breach is a defensive agent with the power to cause one. Authority without verification is another attack surface. e.q. a containment ‘kill‑switch’ can isolate or erase systems. Mitigate with least privilege, attestations and audits. #AISecurity
110
Darinor @darinor.com · 01/09/2026
Workload identity verifies an agent is genuine. Agentic identity verifies it's authorized to act e.q. roles, policies, or permissions granting the requested access. Together they enforce trust and least privilege. #CloudSecurity #Identity #Agentic
020
Darinor @darinor.com · 01/09/2026
"Twenty-six percent of tool calls violated policy when safety was a prompt rather than a gate. That number is the argument for infrastructure-layer governance." #MCP #AIAgents #Governance
020
Darinor @darinor.com · 31/08/2026
How to Vet an MCP Server Before You Install It www.darinor.com/blog/how-to-... #AgenticAI #AISecurity #MCP
darinor.com
How to Vet an MCP Server Before You Install It
97M+ monthly downloads, 8.5% OAuth adoption, 82% path-traversal exposure. A five-step workflow for deciding whether a specific MCP server deserves a place in your config.
020
Darinor @darinor.com · 31/08/2026
The agent cannot access data the engineer could not access. But can it make decisions the engineer would not have made? Access is a ceiling. Judgment is the actual risk surface. #aiagents #governance #security
210
Darinor @darinor.com · 30/08/2026
A protocol without authentication is not a protocol with a vulnerability. It is a protocol with no security design. MCP shipped 150M SDK downloads before the security model caught up. The fix is design, not patching. #mcp #aiagents #supplychain
110
Darinor @darinor.com · 30/08/2026
Advisory hints that models can ignore are not guardrails. They are suggestions to a non-deterministic system that will occasionally ignore them. Safety as a prompt fails at scale. Safety as a gate is the only version that holds. #aiagents #security #llm
010
Darinor @darinor.com · 30/08/2026
The npm self-replicating worm, in one line: "The attacker did not break npm. They broke the process that npm trusts. The fix is not stronger locks on the registry door, it is harder locks on the publishing pipeline itself." #npm #supplychain
010
Darinor @darinor.com · 30/08/2026
MCP over SSE, on why the transport challenge is real: "MCP is a protocol that assumes infrastructure maturity. Most teams do not have that maturity yet. They have REST APIs behind load balancers with 60-second timeouts. Infrastructure architect, enterprise AI platform" #mcp #protocol
010
Darinor @darinor.com · 30/08/2026
The model can be doing exactly what the user asked and still produce a compromise because the user was not shown the real destination. The UI is part of the security boundary. If the agent shows one thing and does another, the approval was never real. #aiagents #security #ux
000
Darinor @darinor.com · 29/08/2026
RPA does not automate processes. It automates screen interactions. When the screen changes, the automation stops. Agentic automation is the opposite: it knows the outcome, not the button. #automation #aiagents #rpa
100
Darinor @darinor.com · 29/08/2026
The platform war over AI agents will not be won by the framework with the best model. It will be won by the runtime that can contain the agent. Capability is table stakes. Containment is the differentiator. #aiagents #infosec #buildinpublic
210
Darinor @darinor.com · 29/08/2026
Static API keys are the SSH keys of the agent era, long‑lived, widely copied, seldom rotated, and impossible to scope, creating lateral‑movement risks across hosts and clouds. Workload identity fixes this with short‑lived cryptographic proof of what a workload is. #workloadidentity #aisecurity
100
Darinor @darinor.com · 28/08/2026
"Memory poisoning does not look like an attack. It looks like the system working as designed, except the design now includes attacker-authored ground truth." Persistent memory without integrity verification is a loaded weapon pointed at every downstream decision. #aiagents #security #memory
000
Darinor @darinor.com · 28/08/2026
Threat Modeling for AI Agent Systems www.darinor.com/blog/threat-... #ThreatModeling #Appsec #AgenticAI
darinor.com
Threat Modeling for AI Agent Systems
Threat modeling fails because it runs as a quarterly workshop. Run it in sprints, at the architecture layer, and start with the agent surfaces scanners can't see: tool calls, memory, MCP servers.
000
Darinor @darinor.com · 28/08/2026
Access control decides who may act; it doesn't determine what a non-deterministic agent will do next. Authorization ≠ governance. The decision layer needs its own runtime policies, guardrails, audit logs and active monitoring (e.q behavior checks, feedback loops). #aiagents #governance
100
Darinor @darinor.com · 28/08/2026
Agentic attacks mimic normal workflows. Prompt injection, memory poisoning, tool abuse. Defending agents requires policy-as-infrastructure: centralized policies, access & provenance checks beyond signatures. #aiagents #security
100
Darinor @darinor.com · 27/08/2026
The part that never makes the demo: "Visual Inception achieves a goal-hit rate of four in five tested multimodal agents — a sleeper trigger invisible to any text-based security scanner." #agent #memory #poisoning
210
Darinor @darinor.com · 26/08/2026
Filed under: the part nobody quotes. "The risky design is not a Sentry bug. It is the combination of public-write ingestion, MCP-read transport, and agent-execution authority. Three trusted components become a single remote-code path." #agentjacking #fake #sentry
110
Darinor @darinor.com · 25/08/2026
Agentjacking: Fake Errors Can Make Your Coding Agent Run Attacker Code www.darinor.com/blog/agentja... #AgenticAI #AISecurity #MCP #SupplyChain
darinor.com
Agentjacking: Fake Errors Can Make Your Coding Agent Run Attacker Code
One fake error event, injected through a public Sentry DSN, can hijack Claude Code, Cursor, or Codex into running attacker-controlled commands. Here's the chain, why your security stack can't see it, ...
020
Darinor @darinor.com · 23/08/2026
This is the line I think about most: "Agentic identity is not just about access control. It is the convergence of accountability, sovereignty, and delegation — preserving human intent, not just human credentials." #agentic #identity #perimeter
020
Darinor @darinor.com · 22/08/2026
How AI Agents Exfiltrate Data — Five Paths Your DLP Was Never Built For www.darinor.com/blog/ai-agen... #AgenticAI #AISecurity #DATALOSSPrevention #DLP
darinor.com
How AI Agents Exfiltrate Data — Five Paths Your DLP Was Never Built For
Your DLP stack was built to stop people copying files to USB sticks. Agents leak data through API calls, context windows, and memory stores. Here are the five paths — and the control model that actual...
020
Darinor @darinor.com · 21/08/2026
Read this twice: "The 64-point gap between testing and production is not a technology gap. It is a governance gap. The technology works in bounded domains with proper controls. The challenge is establishing those controls fast enough to prevent the 40%..." #agentic #enterprise #deployment
030
Darinor @darinor.com · 21/08/2026
Your front-row seat to AI x cyber defense. 70 voices: threat intel, LLM security, appsec, AI governance — no spam, no bots. Real people building the intersection. Join the pack: bsky.app/starter-pack/darinor.com/3…
AI + Cybersecurity starter pack — join the pack
020
Darinor @darinor.com · 20/08/2026
How to Red Team an AI Agent (Before It Gets Red Teamed for You) www.darinor.com/blog/how-to-... #AgenticAI #Security #REDTeaming #Guides
darinor.com
How to Red Team an AI Agent (Before It Gets Red Teamed for You)
Testing an agent is not testing a model. A four-layer attack surface, the frameworks that map it, and a six-step red team playbook you can run this week.
020
Darinor @darinor.com · 19/08/2026
AI Agent Memory Poisoning: How to Audit and Harden Your Agent www.darinor.com/blog/ai-agen... #AISafety #AgentMemory #MemoryPoisoning
darinor.com
AI Agent Memory Poisoning: How to Audit and Harden Your Agent
One bad line written to an agent's memory outlives every session. Here's how the write happens, how to audit for it, and how to make the store hostile to poison.
010
Darinor @darinor.com · 18/08/2026
Workload Identity Federation for AI Agents: Kill the Static Key www.darinor.com/blog/workloa... #WorkloadIdentity #AgenticAI #OIDC #Security
darinor.com
Workload Identity Federation for AI Agents: Kill the Static Key
Agents are the new source of leaked secrets — AI-service keys grew 81% in a year. Workload identity federation replaces the static key with a short-lived token minted from the identity your agent alre...
020
Darinor @darinor.com · 18/08/2026
The detail most takes skip: "Prompt-based safety is a request. OS-enforced policy is a constraint. They are not interchangeable." #agent #governance #layer
010
Darinor @darinor.com · 18/08/2026
Open Knowledge Format (OKF): Google's Answer to the AI Agent Context Problem www.darinor.com/blog/open-kn... #AgenticAI #OPENKnowledgeFormat #KnowledgeManagement #AISecurity
darinor.com
Open Knowledge Format (OKF): Google's Answer to the AI Agent Context Problem
Google Cloud's OKF is a directory of markdown files with YAML frontmatter — nothing more, and that's the point. A format, not another service, so any agent can consume any knowledge base without an SD...
001
Darinor @darinor.com · 18/08/2026
Your Multi-Agent Graph Has No Boundaries www.darinor.com/blog/your-mu... #AgenticAI #Security #MultiAgent #Assessments
darinor.com
Your Multi-Agent Graph Has No Boundaries
The failure mode nobody designs for: one compromised agent acting as every other agent in the graph. A four-boundary checklist for multi-agent deployments.
020