Thinking in public

July 3, 2026 11 min read

Your Security Scanner Is a Supply Chain Too

A post-mortem. The MCP scanner in my local red-team pipeline was defeated by a supply-chain problem, the exact class of risk security tooling exists to catch. One word, two package ecosystems, an acquisition, and weeks of quiet false confidence.

AI SecuritySupply ChainMCPRed TeamOWASP
July 1, 2026 15 min read

The EU AI Act Delay Is Not Relief

The Omnibus is set to push standalone high-risk enforcement to December 2027. Every law firm called it relief. Having built the blueprint, I read it as a deadline for a multi-quarter engineering programme — and the clock starts now.

EU AI ActGRCComplianceAI GovernanceHigh-Risk AIControls
June 19, 2026 28 min read

Red-Teaming an LLM on Your Own Laptop: What Actually Breaks

A field report from building a fully-local, three-layer AI red-team pipeline on an Apple-silicon laptop: 28 fixes, a two-model nightly run, and the honest gap between a local 'pass' and an actual security verdict.

AI SecurityRed TeamMCPLLMOWASPPyRIT
May 29, 2026 10 min read

The Protocol Will Not Save You

Notes on the NSA's May 2026 MCP Security CSI and practical defensive and adversarial work in this space.

AI SecurityMCPNSARed Team
May 2, 2026 15 min read

Building a Secure-By-Design AI Agent with MCP Tools

How to spend a weekend implementing OWASP, NIST, and CSA guidance, and what I learned about where the real security boundaries live.

AI SecurityMCPOWASPNISTCSARed Team

Powered by Buttondown.