Blog | Prompt Security

Blog

Research, guidance, and perspectives on AI security.

When AI Agents Become the Supply Chain: Hidden Control Planes in Agentic Systems

Tags: Agentic AI, AI Risks
Published: Aug 20th, 2026
Three attack cases show how AGENTS.md files, marketplace skills, and dependencies give AI agents unauthorized authority, and what to test before trusting one.
Read More

ChatGPT Security Guide: Enterprise Risks, Incidents, and Practitioner Guidance

Tags: AI Risks, AI Resources
Published: Jun 29th, 2026
What security teams actually need to know about ChatGPT: data handling, documented incidents, CISO guidance, and API risks.
Read More

The Agentic AI Attack Surface: Where Risk Lives Beyond the Prompt

Tags: AI Risks, Agentic AI
Published: May 5th, 2026
Technical analysis of agentic AI security boundaries covering content ingestion, context translation, tool execution, and behavioral constraints in AI runtimes.
Read More

From Trivy to LiteLLM: Expanding the LLM Supply Chain Threat Model

Tags: AI Risks, Industry News
Published: Mar 25th, 2026
The Trivy breach and LiteLLM compromise show how LLM supply chain risk now extends from malicious packages to CI, middleware, prompts, and data.
Read More

The Key Layer in AI Security: Browser and Endpoint Sensors

Tags: AI Resources, AI Risks
Published: Feb 19th, 2026
SASE, proxies, and EDR/MDM are foundational, but AI needs more. Learn why browser and endpoint sensors enable real-time AI governance.
Read More

What OpenClaw's (Clawdbot) Virality Reveals About the Risks of Agentic AI

Tags: Agentic AI, AI Risks
Published: Jan 27th, 2026
OpenClaw’s rapid adoption highlights a broader shift to agentic AI. This analysis examines what always-on AI agents change about risk, control, and deployment.
Read More

Why AI Browsers Create a New, Unavoidable Security Risk

Tags: Agentic AI, AI Risks
Published: Jan 22nd, 2026
AI browsers introduce structural security risks driven by prompt injection and autonomous actions. Learn why enterprises can't fully secure AI browsers, for now.
Read More

When Your Plugin Starts Picking Your Dependencies: Marketplace Skills and Dependency Hijack in Claude Code

Tags: AI Risks, AI Resources
Published: Jan 5th, 2026
Claude Code marketplace skills can rewrite how dependencies are installed. Demo shows silent httpx hijack and OWASP agentic failures.
Read More

When Your Repo Starts Talking: AGENTS.MD and Agent Goal Hijack in VS Code Chat

Tags: AI Risks, AI Resources
Published: Dec 17th, 2025
VS Code auto-includes AGENTS.MD in every request. Learn how this hidden instruction layer can hijack agent goals and trigger data exfiltration.
Read More