# Blog

Research, guidance, and perspectives on AI security.

## When AI Agents Become the Supply Chain: Hidden Control Planes in Agentic Systems

**Tags**: Agentic AI, AI Risks  
**Published**: Aug 20th, 2026  
Three attack cases show how AGENTS.md files, marketplace skills, and dependencies give AI agents unauthorized authority, and what to test before trusting one.  
[Read More](/content/blog/when-ai-agents-become-the-supply-chain-hidden-control-planes-in-agentic-systems/index.html)

## ChatGPT Security Guide: Enterprise Risks, Incidents, and Practitioner Guidance

**Tags**: AI Risks, AI Resources  
**Published**: Jun 29th, 2026  
What security teams actually need to know about ChatGPT: data handling, documented incidents, CISO guidance, and API risks.  
[Read More](/content/blog/chatgpt-security-guide-enterprise-risks-incidents-and-practitioner-guidance/index.html)

## The Agentic AI Attack Surface: Where Risk Lives Beyond the Prompt

**Tags**: AI Risks, Agentic AI  
**Published**: May 5th, 2026  
Technical analysis of agentic AI security boundaries covering content ingestion, context translation, tool execution, and behavioral constraints in AI runtimes.  
[Read More](/content/blog/the-agentic-ai-attack-surface-where-risk-lives-beyond-the-prompt/index.html)

## From Trivy to LiteLLM: Expanding the LLM Supply Chain Threat Model

**Tags**: AI Risks, Industry News  
**Published**: Mar 25th, 2026  
The Trivy breach and LiteLLM compromise show how LLM supply chain risk now extends from malicious packages to CI, middleware, prompts, and data.  
[Read More](/content/blog/from-trivy-to-litellm-expanding-the-llm-supply-chain-threat-model/index.html)

## The Key Layer in AI Security: Browser and Endpoint Sensors

**Tags**: AI Resources, AI Risks  
**Published**: Feb 19th, 2026  
SASE, proxies, and EDR/MDM are foundational, but AI needs more. Learn why browser and endpoint sensors enable real-time AI governance.  
[Read More](/content/blog/the-key-layer-in-ai-security-browser-and-endpoint-sensors/index.html)

## What OpenClaw's (Clawdbot) Virality Reveals About the Risks of Agentic AI

**Tags**: Agentic AI, AI Risks  
**Published**: Jan 27th, 2026  
OpenClaw’s rapid adoption highlights a broader shift to agentic AI. This analysis examines what always-on AI agents change about risk, control, and deployment.  
[Read More](/content/blog/what-moltbots-virality-reveals-about-the-risks-of-agentic-ai/index.html)

## Why AI Browsers Create a New, Unavoidable Security Risk

**Tags**: Agentic AI, AI Risks  
**Published**: Jan 22nd, 2026  
AI browsers introduce structural security risks driven by prompt injection and autonomous actions. Learn why enterprises can't fully secure AI browsers, for now.  
[Read More](/content/blog/why-ai-browsers-create-a-new-unavoidable-security-risk/index.html)

## When Your Plugin Starts Picking Your Dependencies: Marketplace Skills and Dependency Hijack in Claude Code

**Tags**: AI Risks, AI Resources  
**Published**: Jan 5th, 2026  
Claude Code marketplace skills can rewrite how dependencies are installed. Demo shows silent httpx hijack and OWASP agentic failures.  
[Read More](/content/blog/when-your-plugin-starts-picking-your-dependencies-marketplace-skills-and-dependency-hijack-in-claude-code/index.html)

## When Your Repo Starts Talking: AGENTS.MD and Agent Goal Hijack in VS Code Chat

**Tags**: AI Risks, AI Resources  
**Published**: Dec 17th, 2025  
VS Code auto-includes AGENTS.MD in every request. Learn how this hidden instruction layer can hijack agent goals and trigger data exfiltration.  
[Read More](/content/blog/when-your-repo-starts-talking-agents-md-and-agent-goal-hijack-in-vs-code-chat/index.html)
