Blog

Security research, incident analysis, and deep technical writing on governing AI agents in production.

LatestApr 13, 2026·12 min read

Prompt Injection Is Not the Incident

Prompt injection detection is getting better, but what happens when the exploit doesn't look like an exploit? We split a credential-stealing attack across two normal-looking tickets and watched a coding agent execute both. The fix isn't better detection. It's controlling what agents can do.

AD
Anshal Dwivedi

All Posts

Stay in the loop

New research on agent security, identity, and governance. No marketing fluff — just the technical deep dives.