AI Agent Security Blog
The Kontext blog covers AI agent security, agent discovery, access posture, and runtime policy enforcement for teams building with autonomous agents.
Practical writing on AI agents, authorization, MCP, privacy, and production security.
Latest posts
- Kontext Raises $4M to Stop AI Agents From Going Rogue at Work
Kontext raises $4 million led by 42CAP, with backing from a16z CSX and HTGF, to expand its team and build runtime security for AI agents.
- Merlin: Context-aware Local Detection of Unsafe Agent Tool Calls
Merlin evaluates agent tool calls locally using the user request, tool history, and tool schemas to detect unsafe actions before execution.
- How to Really Secure an AI Agent (2026 Guide)
Secure an AI agent with sandbox containment, brokered credentials, enforced egress, runtime authorization, and tamper-evident audit logs for forensic review.
- Kestrel: A local classifier for evaluating the cyber risk of agent tool calls
Coding agents execute shell commands on your machine. We built a local classifier that screens every one of them in ~22 microseconds, and it beats seven frontier LLMs by ~0.40 F1 on ShellRisk-Bench.
- Agent Intent - No One Knows What It Means, But It's Provocative
Why runtime authorization for AI agents should evaluate action safety instead of trying to verify intent, with layered controls for unsafe tool use.
- Announcing Kontext
Introducing Kontext: discover agents, understand their access, and control their actions. Install on your Mac, observe real activity, and enforce policy when ready.
- How to Keep a Secret: Why Personal AI Assistants Like OpenClaw Are a Security Nightmare
A security engineering breakdown of OpenClaw's three critical failure modes: unauthenticated access, credential sprawl, and prompt injection. System model and threat model analysis with practical fixes.
- The 5 Agent Security Failures Your IAM Stack Can't See
Your IAM stack can authenticate people—but it can't authorize what autonomous systems do on their behalf. Five failures that show up the moment your copilot becomes an agent, and what to do about them.
- The API Key is Dead: A Blueprint for Agent Identity in the age of MCP
How to replace static API keys with OAuth 2.0 for MCP agents using scoped tokens, Dynamic Client Registration, delegation, and federation.
- Should You Care About Prompt Injection? (Probably.)
Agents read untrusted content and turn it into actions. Sanitize → detect → enforce at tool boundaries to make that speed survivable.
- Read. Write. Own. Delegate.
The next great leap in the digital age isn't just about ownership—it's about intelligent delegation. Explore how autonomous agents can amplify our capabilities while maintaining our sovereignty.