AI Agent Threat Modeling Guide: Model the Path to Action
Draw an AI agent threat model that connects attacker influence, trust boundaries, identities, controls, and observable asset changes.
Read articleAgentGuard Research
Practical guidance, independent reviews, and clear explanations for teams building AI agents that can take real action.
Draw an AI agent threat model that connects attacker influence, trust boundaries, identities, controls, and observable asset changes.
Read articleTrace sensitive data from source and classification through model context, connectors, recipients, delivery, and safe audit records.
Read articleProtect RAG 2.0 across retrieval, generation, feedback, identity, context assembly, and downstream agent actions.
Read articlePair each prompt-injection prevention control with an owner, adversarial case, target-state assertion, and recovery decision.
Read articleTranslate all ten OWASP agentic AI risks into control surfaces, abuse cases, owners, tests, and retained evidence.
Read articleSecure the complete MCP request path from client identity and transport through server policy, downstream effect, and audit evidence.
Read articleGovern MCP servers and tools from catalog admission through identity, change control, runtime evidence, exceptions, and retirement.
Read articleMake Cursor workspace scope, context exposure, extensions, terminal actions, and branch outcomes separately reviewable.
Read articleConstrain Claude Code workspace access, connected tools, credentials, commands, and repository changes with reproducible checks.
Read articleBuild prompt-injection tests that follow hostile input through tool decisions and verify the downstream target stays unchanged.
Read articleKeep untrusted pages, files, and tool output from changing an AI agent's permissions, destinations, or side effects.
Read articleDetect whether an MCP server is malicious from provenance, component behavior, metadata, telemetry, and target-state evidence, then contain it safely.
Read article