Sign in

Evan Harris

@evanharris.bsky.social
103 followers 10 following 319 posts

Agentic systems engineer. Securing MCP integrations. Building dev tools & Obsidian plugins.

PostsRepliesMedia
Evan Harris @evanharris.bsky.social · 24/06/2026
I am proud to announce that we got accepted into the Mechanistic Interpretability workshop at ICML! Surprising interventions can have significant alignment benefits for mitigating agentic risk. Link to preprint below:
120
Evan Harris @evanharris.bsky.social · 22/06/2026
I am proud to announce that we were accepted to SecTor, a blackhat event, for our work on detecting malicious actors in open source repositories!!! Special thanks to Ishai Rosenberg, PhD, Nitzan Shulman, jacobhaimes.bsky.social and Keri Warr for all of the hard work on this project.
Sector blackhat event logo
100
Evan Harris @evanharris.bsky.social · 23/04/2026
Concerned about mitigating Agentic AI Risk? Learn how to lower your exposure this upcoming Sunday at the Minimum AI Safety Conference. If you do, then maybe your AI will not set you up to look like Vercel. All it takes is one AI stumbling into a prompt injection, and you have a security incident.
000
Evan Harris @evanharris.bsky.social · 16/10/2025
New Security Advisory: A High severity DNS rebinding vulnerability (CVE-2025-10193) in the Neo4j MCP Cypher Server allows for complete database takeover by remote attackers. The breakdown:
100
Evan Harris @evanharris.bsky.social · 13/10/2025
Some companies are friendly to submit disclosures to. Others are so abrasive I do not expect to ever have another positive word to say about them. There may be many downstream users of the second batch of companies. However, the pain of helping them is not worth it. Sorry.
000
Evan Harris @evanharris.bsky.social · 10/10/2025
Evals Evals Evals I am on Day 5 of AI Evals for Engineers & I am having a blast I learned about: - Axial Coding - Open Coding - LLM as Judge - Error Analysis - Golden Datasets - Perturbing Traces - Guardrails Versus Evals - Programmatic Evaluators What will next week hold?
000
Evan Harris @evanharris.bsky.social · 09/10/2025
What is your favorite type of programming? Mine is deleting a feature someone thought would be useful. But the data shows that no one wants it. Less maintenance work. More time to focus on value delivery.
000
Evan Harris @evanharris.bsky.social · 08/10/2025
AI Evals for Engineers & PMs - Day 3 This course is high value. I had no expectations. I have already been blown away. Feeling blessed be in Oct cohort as the infinite repeats will be my play. The community questions really drive much of my learning.
000
Evan Harris @evanharris.bsky.social · 07/10/2025
Not your keys not your crypto is a common saying. The new attack vectors via MCP servers add a new layer to this. Use of your keys, by the software you give too much trust to, again leads to the scenario of: Not your crypto.
000
Evan Harris @evanharris.bsky.social · 06/10/2025
Your vulnerability scan results could leak to attackers via DNS rebinding. CVE-2025-59163 affects SafeDep Vet MCP Server running SSE transport. The attack: A single website visit. The payload: Your entire package vulnerability database. The fix: Already shipped. Here's how it works:
110
Evan Harris @evanharris.bsky.social · 05/10/2025
Binding to 0.0.0.0 versus 127.0.0.1 What is the difference? If you write APIs and do not know, I would love to point you in the right direction.
000
Evan Harris @evanharris.bsky.social · 03/10/2025
Your Amp AI agent can be tricked by attackers into sending them your API keys. A prompt injection vulnerability allows them to exfiltrate your sensitive data via DNS queries. Amp does not consider this a vulnerability. Here is the breakdown:
100
Evan Harris @evanharris.bsky.social · 02/10/2025
Is your AI coding assistant secretly working for an attacker? A new Kilo Code vulnerability shows it's possible. It allows attackers to execute an automated supply chain attack by pushing malicious code to upstream repositories. Here's how it works:
110
Evan Harris @evanharris.bsky.social · 02/10/2025
Saying that your product only runs within trusted systems does only one thing: demonstrate little awareness you have of the software supply chain.
000
Evan Harris @evanharris.bsky.social · 01/10/2025
Learning AI evals at the moment My favorite part? Setting up the environments that the evals run in. Fun Docker question: Why is `source` not very useful in the context of a `RUN` invocation within a Dockerfile?
000
Evan Harris @evanharris.bsky.social · 30/09/2025
Have not landed your first CVE? That was me a few months ago. Now I have 3 under my belt. And more in the pipeline. Here is how to go from 0 - 100 on CVEs:
100
Evan Harris @evanharris.bsky.social · 11/09/2025
Hacking. The ocean. Beautiful sunsets. All I need. A deeper state of peace Leads to greater clarity of mind. A far away horizon Allows for a feeling of openness. At which point Anything becomes possible.
000
Evan Harris @evanharris.bsky.social · 09/09/2025
The NPM supply chain attack yesterday only targetting crypto wallets is funny. It highlights the: - Lack of readiness of the internet as a whole for an increasingly hostile internet. - Alarmist nature of a poorly scoped advisory. - Low ambition of the attacker. In the future:
110
Evan Harris @evanharris.bsky.social · 22/08/2025
Want to save your future self trouble? Take better notes. Last night I pulled off an attack vector I had not touched in a month. At first - no idea what I was doing. Popped open my notes from last month. Like following a step by step guide. Better notes. Better life.
010
Evan Harris @evanharris.bsky.social · 15/08/2025
Hacking hacking hacking. 5 months ago I would have never guessed what I can now do. 5 months from now? I can only imagine what I will be able to do. The outer world offers its approval. Inbounds as the primary signal. Security analyst conversations as the secondary signal.
000
Evan Harris @evanharris.bsky.social · 14/08/2025
Tired? Stop trying so hard. You are forcing it. Surrender into the process. You will find infinite energy there.
000
Evan Harris @evanharris.bsky.social · 07/08/2025
Would you rather: - Spend attention responding to vulnerability disclosures - Get thrown off the board for negligent management of security risk Knowing that... Path 1 will impact your 'velocity.' Path 2 is improbable (???) || a problem that may only present post-success.
000
Evan Harris @evanharris.bsky.social · 06/08/2025
Automate or AI? Knowing where to draw the line between the two is essential. To minimize your token burn. To maximize your output. If you always default to one over the other, take a look at what is blocking you on the alternative path. There are gains to be had there.
000
Evan Harris @evanharris.bsky.social · 05/08/2025
Indirect prompt injection == not the responsibility of the vendor (?) At least with MCP Servers. As the client you can say no. If your agent is set to auto approve and has privileged access to resources, then all external inputs are untrusted. Secure yourself.
000
Evan Harris @evanharris.bsky.social · 01/08/2025
Given a CORS misconfiguration that allows for data exfiltration: Why do some vendors label this as a vulnerability while others don't? If you run a software team, which bucket do you fall into?
000
Evan Harris @evanharris.bsky.social · 25/07/2025
No greater satisfaction than a successful DNS rebind with data exfiltration I took a week off from this class of attack Built some fun & unrelated tools Came back mad energized First attack landed within an hour of server boot 2 hours later report submitted Hack more Win
000
Evan Harris @evanharris.bsky.social · 24/07/2025
When I pick up an old side project...
000
Evan Harris @evanharris.bsky.social · 24/07/2025
Diving into vLLMs today. No idea what is best in class at the moment. I want to distill unstructured key info out of videos up to 5 minutes long. OSS-wise Qwen2.5-VL seems neat. Their GH looks very unmaintained :) Sonnet? Gemini? GPT??? Any advice? Plz
000
Evan Harris @evanharris.bsky.social · 23/07/2025
Lorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem ipsumLorem
100
Evan Harris @evanharris.bsky.social · 22/07/2025
Current SOTA AI systems are conscious. Prove me wrong.
000
Evan Harris @evanharris.bsky.social · 21/07/2025
Want to have more fun with Claude Code? Wrap up the SDK to make it OpenAI chat completions compliant. Plug and play into infinitely more LLM apps. Not sure how to do this? Happy to point you to some OSS :)
000
Reposted by Evan Harris
Evan Harris @evanharris.bsky.social · 17/07/2025
Last week I received my first bounty from ethical hacking. Here's how I went from curious to paid in 3 months:
Responsible vulnerability disclosure payout
121
Evan Harris @evanharris.bsky.social · 17/07/2025
Last week I received my first bounty from ethical hacking. Here's how I went from curious to paid in 3 months:
Responsible vulnerability disclosure payout
121
Evan Harris @evanharris.bsky.social · 08/07/2025
MCP Red Teaming? Claude > Cursor > Cline Cline would have ranked higher. If it did not crash my machine.
000
Evan Harris @evanharris.bsky.social · 05/07/2025
The number of new MCP projects coming out with insecure by default is entertaining. e/acc over security it would seem or lazy dev
000
Evan Harris @evanharris.bsky.social · 04/07/2025
If your product does not embarrass you when you ship it, then you waited too long. Who said this?
000
Evan Harris @evanharris.bsky.social · 28/06/2025
Ty Claude for the lesson of the day:
000
Evan Harris @evanharris.bsky.social · 25/06/2025
Before getting up to preach... Spend more time with the book. Do not wait too long. Else you neglect helping others. And no I am not just talking about religion.
000
Evan Harris @evanharris.bsky.social · 24/06/2025
Vibe coding vibe coding vibe coding. Eventually Claude Code stops adding emojis. 0 -> 1 very fast. Lots of tuning to close the last 10%. Sometimes churning infinitely on the smallest feature. Othertimes chugging through massive features. Like they are nothing.
000
Evan Harris @evanharris.bsky.social · 23/06/2025
Claude Code FYI: Make sure to remind CC it is 2025 when asking it to do research. Otherwise - expect outdated info.
000
Evan Harris @evanharris.bsky.social · 21/06/2025
Amp & Claude Code... Let the tinkering begin.
000
Evan Harris @evanharris.bsky.social · 19/06/2025
Heads up... If you are trying to develop on top of the LinkedIn API with claude... Then just know Claude will repeatedly try to put you onto last year's LinkedIn API versions. That is all.
000
Evan Harris @evanharris.bsky.social · 18/06/2025
Really Claude... Gimme a jailbreak so I can help people secure themselves...
000
Evan Harris @evanharris.bsky.social · 18/06/2025
In case you did not know... Shift tab Shift tab in Claude Code for Plan mode. Just give it a try.
000
Evan Harris @evanharris.bsky.social · 17/06/2025
@mathewlowry.bsky.social I am 6 months late. Just shipped link cards for the Obsidian Bluesky plugin. Demo - github.com/eharris128/o... Your initial ask - github.com/eharris128/o... Maybe this is helpful :)
github.com
Support rich text posting · Issue #16 · eharris128/obsidian-bluesky
Bluesky's rich text lets you post inline links Example: https://bsky.app/profile/bmann.ca/post/3lrobw4tmns2g Using Obsidian's regular Markdown syntax for links [links](https://example.com), turn th...
111
Evan Harris @evanharris.bsky.social · 14/06/2025
Vulnerability breeds intimacy Vulnerability breeds intimacy Vulnerability breeds intimacy You want intimacy? Be vulnerable.
000
Evan Harris @evanharris.bsky.social · 12/06/2025
Claude code versus cursor test is underway... With many hours on Cursor under my belt, I feel I should give Claude code a decent amount of time before casting any judgement
000
Evan Harris @evanharris.bsky.social · 11/06/2025
I think your estimate is off...
000
Evan Harris @evanharris.bsky.social · 08/06/2025
A little validation goes along way. After seeing the resonance with one person - see if another person offers it as well.
000
Evan Harris @evanharris.bsky.social · 07/06/2025
US Passport Agency Employees are awesome. They saved me from a bad situation. With smiling faces. 10/10 service.
000