Security
We Automated Dave: …
This is a personal blog. All opinions are my own - not my employer’s. There’s apparently a new category of security incident called AI escape. Except there isn’t. That phrase might be useful shorthand for headlines, and some of the incidents behind it are genuinely serious, but I think …
Prompting Was Never the …
This is a personal blog. All opinions are my own - not my employer’s. At some point over the last few months, I accidentally built a control plane for coding agents. This was not the plan. The plan, to the extent that there was one, was much smaller and much more normal. I wanted coding agents to …
ISeeMP
ISeeMP (I See Model Paths) builds a deterministic graph of source-to-context-to-sink capability paths across agent and MCP toolchains. What it does Classifies tool capabilities with rule-based analysis Generates path graphs without requiring an LLM in the loop Flags high-risk combinations, including …
coding-agent-baselines
coding-agent-baselines is a modular instruction-pack repository for GitHub Copilot coding-agent workflows. It helps teams compose reusable guidance and apply it consistently across projects. What it does Ships baseline instruction packs for common engineering constraints Supports composable policy …
FinOps for Delegated …
A few weeks ago I wrote about what I was then calling the Agile Agentic Development Life Cycle, or AADLC …
WhereMyMVPsAt
WhereMyMVPsAt is the public-facing issue and feedback channel for the project, with clear guidance on what belongs in intake. What it does Provides templates and structure for bug and feature submissions Offers a public process for coordinated security reporting Separates issue intake from private …