These collections are a better place to begin than the chronological archive. Each one connects the essays that build on the same underlying problem.
Agent and MCP Security
AI agents turn language into actions. That makes identity, delegated authority, tool permissions, and execution integrity part of the security boundary—not implementation details. Start here Trust Is the Next Bottleneck explains why authorization alone cannot establish that an agent is running the expected code. AI Agents Have an Identity Crisis examines verifiable delegation across multi-agent workflows. MCP Is a Capability System provides the practical permission model. Hardening MCP Servers with Confidential Computing addresses the infrastructure trust boundary around tool credentials. Google’s AP2 Protocol applies these ideas to agent-initiated commerce. Together, these essays describe a security model built from bounded authority, measured execution, and evidence that survives every hop.