Skip to content
AgenticCyber

Personal blog · security notes and projects

Secure every hop your AI agents make.

Notes and working projects on securing agentic AI: identity, policy and audit on agent-to-agent, agent-to-LLM and agent-to-tool traffic. I build small proofs of concept in my own time and share the code and what I learned.

coverage

Three paths, one policy point

A → LLM

Agent to LLM

  • Virtual keys per agent
  • Prompt guards and redaction
  • Token and budget limits

A → MCP

Agent to tools (MCP)

  • Authenticated tool access
  • Per-identity tool scoping
  • Guardrails on tool calls and responses
  • Audit trail

A → A2A

Agent to agent (A2A)

  • An identity for every agent
  • mTLS
  • Authorization on each hop
  • End-to-end tracing

projects

Latest project

PublishedPROJECT-001

Securing agent traffic with an open-source agentic gateway

I put agentgateway in front of an LLM and an MCP tool server on kind and walked it through the six NIST CSF functions, with a script that proves each control.

Read the project →

notes

Latest notes

All notes →

feedback

Found a mistake, have an idea, or want to talk about agentic security? Open an issue on GitHub or get in touch.