the journal · by tag
Security
Every post filed under Security, newest first, one register of 7 the journal keeps. The shelf lens on the journal filters the same set in place.
- 007postsin this register
- 017tagsthe journal keeps
- 0249posts in the journalall registers together
- 032026-08-21latestnewest first below
07Clean is not ready to spendA valid AI workflow can still waste money. Nika now separates legal files from workflows that are ready for a paid run.06The CI job should know its boundaryRun Nika in CI and on headless servers with the same checked workflow bytes, explicit authority, deterministic rehearsals and a hard launch budget.05MCP with a blast radiusAn MCP tool is executable foreign capability. Put its server, network, environment, tool ids and schema pin under separate review, then let the trace record the call.04The prompt injection that goes nowherePrompt injection examples usually end with the agent taking a new action. Here the plan is authored before the model runs: the hostile note becomes data, never an action, and the boundary is checked before a token is spent.03The credentials your pipeline was breakingOpenAI and Google sign the images their APIs return. Almost every pipeline that touches those files silently converts the signature into evidence of tampering. That included ours, until this week.02The secrets lineInformation-flow, audited before it flows: how the checker proves a secret cannot leak into a prompt, a file, or a host.01The blast radius is part of the fileThe workflow declares its effect boundary before execution. Static checks explain the fit; runtime sinks enforce what the host can prove.