Writing

Read the source, then write down what it actually says

I build the evidence layer for AI agents, and I write about where it does not hold yet. Every figure below was read at its primary source, every note lists what it was checked against, and where a source did not support a claim the claim is not here.

Notes

Short, dated, and sourced. RSS

The fix shipped three weeks before the bug had a name

agent-securitysupply-chaincoding-agents

The finding was correct and eight weeks late

attestationtlsspec-review

Two normative sentences went missing when one tasks spec superseded another

mcpagent-securityspec-review

The tool list was advertised, the resolver decided

agent-securitytool-callingenforcement

The MCP registry checks that the repository URL looks like GitHub

agent-securityprovenanceregistries

The platform bit that means the opposite of what the doc says

attestationsev-snpevidence

The attestation everyone cites cannot be looked up any more

supply-chainevidenceprovenance

What the encrypted reasoning paper actually counted

agent-securityevidenceretention

Two of the three endpoints checked authorization

agent-securityapiauthorization

Essays

Longer pieces, published on dev.to and cross-posted to Medium.

What a signature does not prove

attestationevidence