topic · 2 notes
Agent Security, as it ships.
Engineering notes on Agent Security by Samir Sengupta - each one read from primary sources on the day it happened, with what it changes for people building on it.
August 7, 2026 · Agent Security · Permissions · Supply Chain Security
Humans miss a third of malicious agent commands, so stop putting them in the loop
40,000 runs and 409,000 approve/deny decisions: players missed a third of threats, and 64.7% approved an npm run script whose exfiltration payload was printed on screen.
August 7, 2026 · Agents · Tool Calling · LLM Evaluation
Programmatic tool calling matched or beat JSON on 11 of 14 models
On BFCL v4, programmatic tool calling matched or exceeded native JSON calls in 11 of 14 models, hit +10.6% on GPT-5.6, and stayed flat under context rot where JSON dropped 2.3%.
Hiring for AI or ML?
I am open to AI/ML Engineering, Data Science, and Python roles, plus research collaborations and consulting. New York based, shipping worldwide.