Skip to main content
Agentic AI Security Field Guide

Secure the agents before they touch the workflow.

Practical research for humans and agents — MCP risk, prompt injection, identity, tool trust, and the controls that keep blast radius visible.

No pricing, SOWs, or service funnel. Just field notes you can use.

Not a policy deck.

Every resource should give you a test, checklist, Skill, or workflow pattern you can use.

Not AI hype.

Workflow controls come before tool recommendations.

Not unmanaged automation.

Actions, approvals, and recovery paths stay visible before AI gets more authority.

Short answer

What does VibeSec Advisory help builders do?

VibeSec Advisory helps builders understand and test the risks created by agents, MCP servers, AI coding tools, prompt injection, and AI-generated workflows.

Read the latest field notes
Latest field notes

Practical notes on agents, MCPs, prompt injection, AI coding tools, and safer workflows.

Essays, checklists, Skills, and field notes for people building and testing AI systems.

Explore all writing
Agentic AI Security

Don’t Reuse Human Identity for Agents

Give the agent its own declared identity, bound to a principal chain that names who authorised it. Check declared versus observed behavior. Do not treat a reused human session, shared API key, or parent-token passthrough as the agent’s identity.

Read field note
Agentic AI Security

Bind MCP Approval to Content, Not the Tool Name

Bind approval to a canonical content hash of the executable configuration and tool definition—not to the tool name. If the hash changes, treat it as a new consent event and ask again.

Read field note
Agentic AI Security

Use the OWASP Agentic Top 10 as a Test Plan, Not a Badge

Use the OWASP Agentic Top 10 as a row-per-risk test plan with harmless probes, denial evidence, owners, and retest triggers before expanding agent access.

Read field note
AI Workflows Weekly

A weekly briefing for builders securing agentic AI.

Practical notes on agent security, MCP risk, prompt injection, AI coding tools, and safer workflows. The website stays the home base for deep guides. The newsletter gives readers a simple way to keep up.

No generic AI tool roundup. No hype feed. Field notes on agent boundaries, MCP permissions, prompt injection risk, human review, and the operating model around AI at work.

AI Workflows Weekly

Read the archive

Practical notes on governed AI workflows, guardrails, and safer automation. No spam, unsubscribe anytime.

First-party signup with double opt-in. No embedded newsletter iframe, no analytics cookies, and unsubscribe anytime.

The problem

AI adoption without workflow design creates invisible risk.

People are using copilots, agents, and MCP-connected tools inside live business processes. The question is no longer whether AI is being used. The question is whether the workflow has a baseline, reusable skills, permissions, review points, and a measurement loop.

Workflow first

Start with the process, owner, inputs, approvals, and failure modes before tools.

Business metrics first

Good workflow review starts with the current metric, owner, and target state.

Guardrails by design

Human checkpoints, data boundaries, action limits, escalation, and security are mapped together.

Evidence before claims

Write down what you tested, what failed, what changed, and what still needs review.

Use The Field Guide

Start with the research, then use Skills when you need patterns.

The public front door is the research. Skills stay available as a real destination for reusable procedures and guardrails. Each resource should help you understand a risk, test an agent, review a tool, or improve a workflow.

Start here

Agentic AI Security Research

Read field notes on agents, MCPs, prompt injection, AI coding tools, generated code, and practical security workflows.

  • Prompt injection tests
  • MCP security notes
  • AI red-team lessons
Read the research
Operating artifacts

Skills

Browse reusable AI workflow skills, guardrails, examples, and implementation patterns that show how governed work should be captured.

  • Reusable procedures
  • Review gates
  • Data boundaries
Browse Skills
FORGE

A six-pillar model for agent-ready work.

FORGE remains a historical and educational model for thinking about governed workflows. The active VibeSec Advisory direction is a free field guide for securing agentic AI.

FORGE pillar

Baseline

Current workflow, owner, source system, pain point, and target metric.

FORGE pillar

Skills

Reusable instructions that capture how expert work should be done and reviewed.

FORGE pillar

Agents

Automation only where the tool boundary, action limit, and recovery path are known.

FORGE pillar

Guardrails

Data boundaries, approval gates, escalation rules, and security controls.

FORGE pillar

Schedule

Triggers, cadence, dependencies, and failure handling for repeatable work.

FORGE pillar

Capture

Evidence, lessons, regression checks, and the next measurable improvement.

How we work

Less strategy theater. More usable operating artifacts.

Capture

Capture reusable Skills, source boundaries, review gates, and test results so workflow knowledge compounds.

Map

Map agents to concrete steps, owners, tools, review points, and failure modes before trusting automation.

Contain

Guardrails are designed as blast-radius controls, not vague policy language.

Measure

Every artifact should include a way to test, review, or improve the workflow.

Start with the systems your agents can touch.

Read the latest field notes, then use Skills to test your own agentic AI systems.