AcademyResourcesCompanyResearchFree risk assessmentBook a demo ↗
/ Resources

Field notes on securing & governing AI.

Deep-dive research, practical guides, illustrated explainers and field tools — agentic-AI threats, defenses, and the controls that hold up to audit.

Filter by track
WhitepaperNew

Anatomy of an Eval Escape: The OpenAI–Hugging Face Incident

A 17-page technical analysis of how an agent evaluation broke containment through build infrastructure almost no one classifies as a security boundary — what happened, what's still unknown, and 15 tests to run in your own environment. Every claim carries a confidence label.

  • incident analysis
  • agent evaluation
  • containment
Threats · PDFDownload the report →
ResearchNew

Indirect prompt injection in tool-using agents

When an agent reads attacker-controlled content, that content can become instructions. The anatomy, the blast radius, and the controls that contain it.

  • prompt-injection
  • agents
  • rag
Threats · 14 min readRead more →
ResearchNew

Securing Agentic AI: Why Autonomy Changes the Risk Model

Traditional AppSec assumes a human acts on the model's output. Agents remove the human. When output becomes action, the risk model has to change with it.

  • agents
  • autonomy
  • attack-surface
Threats · 9 min readRead more →
ResearchNew

Prompt Injection: The #1 Risk Every AI Product Team Must Understand

Why the top risk in the OWASP LLM Top 10 is a design property, not a bug — and what that means for every team shipping AI.

  • prompt-injection
  • llm-top-10
  • agents
Threats · 10 min readRead more →
ResearchNew

The New AI Attack Surface: Model, RAG, Tools, Memory, Identity

Securing the model is one-fifth of the job. A component-by-component tour of where AI systems actually get attacked.

  • attack-surface
  • rag
  • tool-use
Threats · 11 min readRead more →
ResearchNew

The Lethal Trifecta: Injection + Sensitive Data + Tool Access

Three capabilities that are each fine alone become a data-exfiltration engine when combined. The frame every agent design should pass through.

  • lethal-trifecta
  • prompt-injection
  • agents
Threats · 8 min readRead more →
ResearchNew

What Is Agentic AI Red Teaming?

Why testing an autonomous agent isn't chatbot QA and isn't a pentest — and what a real agentic red team actually does.

  • red-teaming
  • agents
  • methodology
Defense · 9 min readRead more →
Comic

OWASP LLM Top 10, illustrated

The ten biggest LLM application risks — explained as a visual story for the whole team, not just security.

  • owasp
  • llm-top-10
  • education
Governance · External ↗Read the comic →
Comic

OWASP Agentic AI Top 10, illustrated

What changes when AI can act: the agentic risk classes, drawn out panel by panel.

  • owasp
  • agentic
  • education
Threats · External ↗Read the comic →
eBook

The Architecture of Intelligence

A framework for understanding AI agent systems — how they're built, and where security and governance have to live inside that architecture.

  • architecture
  • agents
  • platform
Defense · PDFDownload the PDF →