g

654 posts

g

g

@honeybadgerhack

infosec, breaky-breaky, AppSec, world traveler, surfer of hydrofoils, bjj brown belt. https://t.co/nJaGqsN0Fe

Katılım Nisan 2019
201 Takip Edilen70 Takipçiler
g
g@honeybadgerhack·
@ZackKorman This is why I built assury.ai it happened to me last year
English
0
0
0
25
g
g@honeybadgerhack·
@ZackKorman Hey Zack I like this approach. I built assury.ai and have some experimentation on the detection side. I would love to chat about this. Assury is execution layer governance not detection but we have some really interesting telemetry.
English
1
0
1
112
Zack Korman
Zack Korman@ZackKorman·
New video on AI agent threat detection. What works, what doesn't, and why no approach is perfect. I also go into detail on how I do things. I spent way too much time making this, so please watch.
English
20
32
153
17.9K
g retweetledi
Zack Korman
Zack Korman@ZackKorman·
This new AIUC-1 "AI agent compliance standard" is a massive grift. Everyone involved is taking something for themselves. The "losers" here are the companies that might rely on this thinking it means something and the startups that will have to pay to get audited.
English
29
17
144
26.7K
g
g@honeybadgerhack·
MoCoP is the first production platform built specifically for AI agent runtime governance at the execution boundary. ✓ Intercepts tool calls before execution ✓ Session-level cumulative risk scoring ✓ OPA/Rego deterministic policy — no LLM in the governance path ✓ Credential starvation — agents never hold tool credentials directly One deployment. No SDK.
English
1
0
0
38
g
g@honeybadgerhack·
Model governance ≠ action governance. Model gateway: which models, cost controls, rate limits. Assury Enforce: which tools, under what conditions, with what session context. Different boundary. Different problem.
English
0
0
0
6
g
g@honeybadgerhack·
API gateway adoption is accelerating in AI teams. So is the false sense of security it creates. New post on the architectural gap nobody's drawn yet: assury.ai/blog/why-api-g…
English
0
0
0
9
g
g@honeybadgerhack·
Your input filter passed. Your output filter passed. Your tool call wasn't filtered. That's not a prompt security failure. That's a category error.
English
0
0
0
11
g
g@honeybadgerhack·
Post-inference is the new attack surface. Most stacks have zero coverage there. The LLM decides what to do. The tool call is where it actually happens.
English
0
0
0
1
ナタリー 🌙
ナタリー 🌙@natalie_avfieb·
@honeybadgerhack Post-inference is exactly the blind spot. When an agent acts on an MCP tool response, it's treating external content as trusted execution commands. If that layer goes unmonitored, prompt injection flows straight to the tool.
English
1
0
0
8
g
g@honeybadgerhack·
Lakera, LLM Guard, Prompt Security: they stop bad inputs. They miss everything after. Post-inference is ungoverned. That's where agents do real damage. Free dev tier → assury.ai #MCP #AIAgentSecurity
English
1
0
1
30
g
g@honeybadgerhack·
@elonmusk Not with Assuy.ai governance at the execution-path
English
0
0
0
3
Elon Musk
Elon Musk@elonmusk·
Giving people agentic AI be like …
English
6.1K
8.9K
108.7K
50.2M
g
g@honeybadgerhack·
Okta, Entra, CyberArk -- great at who. Silent on what. Authentication ends at the door. Governance starts inside. assury.ai
English
0
0
0
21
g
g@honeybadgerhack·
A new arXiv spec defines what AI agent runtime governance must include. We contributed to it. MoCoP is the reference implementation. arxiv.org/abs/2602.09433
English
0
0
0
17
g
g@honeybadgerhack·
One endpoint. 15 minutes. No SDK. Full AI agent governance. No rewrite. No framework dependency. No months of integration. That's Assury MoCoP.
English
1
0
0
12
g
g@honeybadgerhack·
Three billion-dollar security categories. Zero of them govern what AI agents actually do. New post on why identity, prompt security, and API gateways all miss the same layer: assury.ai/blog/ai-securi…
English
0
0
0
4
g
g@honeybadgerhack·
The 5-layer AI stack: L5: Identity ✓ L4: Prompt security ✓ L3: Model routing ✓ L2: Tool & action governance ✗ L1: Autonomy governance ✗ Two layers. Zero coverage. That's the problem. Assury MoCop solved
English
0
0
0
14