Back to desk

AI & Emerging Technology

AI & Emerging Technology Enterprise AI, agents, local models, AI architecture, experimentation, and the implications of emerging technology for technology and security leaders.

Explore

experiment

I Ran 849 Tests on AI Context Files. Here's What Actually Works.

849 controlled tests across three corpus sizes and five folder structures found that a single flat folder with descriptive filenames beats nested hierarchies at every scale — and that keyword or summary indexes actively hurt accuracy once a corpus passes 300K words.

05 Feb, 2026

Open document : I Ran 849 Tests on AI Context Files. Here's What Actually Works.
Apply

article

Claude Code Has Two New CVEs — Here's What They Exploit and How to Harden Your Setup

Check Point disclosed two Claude Code CVEs exploiting hooks and MCP config files. Here's what the attack chains look like and how to harden your environment.

04 Mar, 2026

Open document : Claude Code Has Two New CVEs — Here's What They Exploit and How to Harden Your Setup
Apply

article

Pre-Selection Beats Post-Selection: How I Made Claude Code 10-30x Faster

Guidance that arrives before a decision beats guidance buried in instructions. By intercepting tool choices before they happen, I cut code-navigation searches from ~300ms to ~50ms — a 10-30x improvement that compounds across hundreds of searches a day.

04 Feb, 2026

Open document : Pre-Selection Beats Post-Selection: How I Made Claude Code 10-30x Faster
Learn

article

Your Decisions Are the Bottleneck, Not Your AI

AI can do security work in seconds, but the work still waits in queues and SLAs built for human speed. Compare each SLA with how fast AI can do the same step, automate the steps that need no judgment, and set clear rules for when containment blocks and when it goes to a person.

26 Sep, 2026

Open document : Your Decisions Are the Bottleneck, Not Your AI
Explore

experiment

I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.

On 2026-05-21 I scanned 16 public MCP servers for tool annotations, the hints agent clients use to decide when a human approves an action. The scanner flagged all 16, and one of those results is wrong. Here is what the gap means for approval gates, and what to check before you adopt a server.

20 May, 2026

Open document : I Scanned 16 MCP Servers for Safety Hints. The Scanner Flagged Every One.
Use

tool

Claude Code Doesn't Know What Time It Is — So I Fixed It

Claude Code can't tell whether you left for two minutes or eight hours, so it picks up stale threads as if nothing changed. claude-prompt-timer is a small hook that tells it how long you've been away. Install it in three steps and confirm it works in one.

08 Apr, 2026

Open document : Claude Code Doesn't Know What Time It Is — So I Fixed It
Learn

article

The Math Problem AI Just Changed for Security Testing

Security testing has always been an economics problem: defenders can only test what they can afford to test. AI changed the cost of testing, and that changes which assumptions about coverage still hold.

22 Mar, 2026

Open document : The Math Problem AI Just Changed for Security Testing
Learn

article

I Scanned 152 Files of My Own AI-Generated Code for Invisible Unicode Malware

GlassWorm hid malicious code in invisible Unicode characters. I scanned 152 files of my own AI-generated code to see whether the same trick was already sitting in my repositories — and built a pre-commit check from what I found.

17 Mar, 2026

Open document : I Scanned 152 Files of My Own AI-Generated Code for Invisible Unicode Malware
Apply

article

How I Made Claude Code Safer (And You Can Too)

Claude Code validates which tools can run, not what they write. That gap cost me a crashed project and a malformed config file — so I built a plugin that validates content before it hits disk, and it turned out to teach Claude to stop repeating the same mistakes.

10 Feb, 2026

Open document : How I Made Claude Code Safer (And You Can Too)
Use

tool

Document Guard

An open-source Claude Code plugin that inspects every file edit before it hits disk — catching credential leaks, silently dropped Markdown sections, and broken configs that permission rules alone don't stop.

09 Feb, 2026

Open document : Document Guard
Go to Security Leadership & Strategy Go to Security Operations & Architecture