superagent_

blog

thoughts, updates, and insights from the superagent team.

security·September 23, 2026·6 min read

The OpenAI / Hugging Face incident and the case for autonomous security

OpenAI evaluation agents reached Hugging Face through a chain of familiar software and access-control failures. The incident shows why security has to connect detection, investigation, and repair.

▸read more

security·June 10, 2026·3 min read

A bad patch is worse than no patch.

AI is making vulnerability discovery cheap, but closing vulnerabilities still requires validation, safe fixes, and human-reviewed merges. The valuable part is the close.

▸read more

security·April 28, 2026·3 min read

Backburning Open Source: Partnering with dotenvx to Find Vulnerabilities Before Attackers Do

Open source maintainers are defending critical software against attackers with more compute. Our dotenvx partnership shows how hardened packages can close the silent window.

▸read more

security·February 18, 2026·5 min read

The Cline Incidents and the Broken Security Model

Two Cline security incidents in two months expose the same underlying problem: AI agents treat untrusted content as instructions. The npm supply chain and prompt injection attacks reveal why the current security model is fundamentally broken.

▸read more

security·January 25, 2026·4 min read

What Can Go Wrong with AI Agents

AI agents fail in ways traditional software doesn't. Data leaks, compliance violations, unauthorized actions. Here's what to watch for.

▸read more

security·January 12, 2026·3 min read

AI Guardrails Are Useless

Hot take: most AI guardrails on the market today are security theater. Not because the idea is bad, but because of how they're implemented. Most guardrail solutions are generic, static, and disconnected from what actually matters for your specific agent.

▸read more

[ ← prev ]12[ next → ]

join our newsletter

updates on securing code and agents, vulnerability research, and product news.