Independent AI security research

Secure the agents before they act.

Practical research, detections and security controls for AI agents, coding assistants and autonomous systems.

Understand how agents interact with tools, credentials, source code and enterprise systems—and how to observe, control and investigate their actions.

Architecture Threat Model
AI Agent Tools APIs Enterprise Sys 1 2 3
1 Identity
2 Policy
3 Telemetry
4 Detection / Response

AI agents create a new security boundary.

AI agents can execute commands, access files, call external services, modify source code and use enterprise credentials. Traditional logs may record the action without clearly showing whether it was initiated by a human, an AI assistant or an autonomous workflow.

Agents can act

They can execute commands, modify resources and trigger complex enterprise workflows autonomously.

Agents can access

They may reach source code, secrets, internal APIs, cloud systems and highly sensitive data.

Agents are difficult to attribute

Human and agent actions often look identical in existing audit logs, hindering investigations.

Latest research

View all articles →
Threat Modelling

MCP security threat model

A practical analysis of trust boundaries, tool permissions, prompt injection and server compromise in Model Context Protocol environments.

Sep 28, 2025 12 min read
MCP Agent Security
Identity & Attribution

Human or AI agent?

Why audit logs struggle to distinguish human actions from autonomous activity, and how to fix the attribution gap.

Sep 14, 2025 6 min read
Identity Telemetry

Research grounded in real telemetry

Our methodology relies on practical experimentation, active data collection, and validated engineering.

1

Observe

Agent behaviour

2

Collect

Logs & telemetry

3

Model

Attack paths

4

Build

Detection controls

5

Test

Workflows

6

Publish

Findings

AI Agent Security Readiness Checklist

A practical checklist for evaluating coding assistants, MCP servers and autonomous agents before enterprise deployment.

  • Agent identity
  • Authentication
  • Tool permissions
  • Secret access
  • Logging
  • Human approval

Occasional technical updates. No marketing noise.

Practical AI security engineering

Watch hands-on implementation and architecture reviews on YouTube.

@AgentSecurityLab
14:22

How to detect AI coding-agent activity

Building robust detections using OpenTelemetry logs from popular dev tools.

Watch video →
22:15

MCP security explained

Understanding the Model Context Protocol, trust boundaries, and authorization models.

Watch video →
18:40

Building detections for agent tool abuse

Practical examples of SIEM queries for detecting excessive agent permissions.

Watch video →

About Agent Security Lab

Agent Security Lab is an independent technical research project focused on securing AI agents and AI-assisted development environments.

The lab studies how autonomous systems interact with enterprise identities, tools, source code, cloud environments and sensitive data. We focus on evidence-based research rather than marketing, operating as a dedicated engineering publication for security practitioners.

The objective is to turn emerging AI security risks into practical controls, telemetry strategies and deployable detections.

Follow the research

Receive new detection ideas, technical experiments and implementation guidance for securing AI agents.