AGPL-3.0-or-later · forever.

the journal · by tag

Security

Every post filed under Security, newest first, one register of 7 the journal keeps. The shelf lens on the journal filters the same set in place.

  • 7postsin this register
  • 7tagsthe journal keeps
  • 49posts in the journalall registers together
  • 2026-08-21latestnewest first below
07Clean is not ready to spendA valid AI workflow can still waste money. Nika now separates legal files from workflows that are ready for a paid run.2026-08-21 · 6 min06The CI job should know its boundaryRun Nika in CI and on headless servers with the same checked workflow bytes, explicit authority, deterministic rehearsals and a hard launch budget.retrospective · 2026-08-15 · 8 min05MCP with a blast radiusAn MCP tool is executable foreign capability. Put its server, network, environment, tool ids and schema pin under separate review, then let the trace record the call.retrospective · 2026-07-24 · 6 min04The prompt injection that goes nowherePrompt injection examples usually end with the agent taking a new action. Here the plan is authored before the model runs: the hostile note becomes data, never an action, and the boundary is checked before a token is spent.2026-07-08 · 3 min03The credentials your pipeline was breakingOpenAI and Google sign the images their APIs return. Almost every pipeline that touches those files silently converts the signature into evidence of tampering. That included ours, until this week.2026-07-06 · 4 min02The secrets lineInformation-flow, audited before it flows: how the checker proves a secret cannot leak into a prompt, a file, or a host.2026-07-05 · 3 min01The blast radius is part of the fileThe workflow declares its effect boundary before execution. Static checks explain the fit; runtime sinks enforce what the host can prove.retrospective · 2026-06-12 · 3 min

The other registers: Engine · Sovereignty · Agents · Language · Manifesto · Origins. The whole journal →