// Archive
Agent architecture & containment
Harness design, tool-call validation, multi-agent boundaries, and the containment choices that decide what an agent can do before anything goes wrong.
// Reference
The attack surface, mapped →
Every technique and tool from this category, organized by layer.
Categories
- NOT-008CSP Nonces and the Same-Origin Policy Solve Different ProblemsA CSP nonce and the same-origin policy both show up in the same sentence about XSS, but they guard different boundaries — one says which script on this page is allowed to run, the other says which origin is allowed to read what. Confusing them leaves one of the two unguarded.#appsec#web-security#csp6 min read
- NOT-007Agent Containment Is an Environment PropertyAn approval dialog is a request for the agent to be trusted. Containment is what stays true when that trust fails — and it lives in the environment, not the model.#agentic-ai#ai-security#agent-architecture9 min read
- NOT-006How to Build an Agent Harness That Doesn't Waste Your ModelSame weights, different harness: fail-to-pass 28%→49%, complete solutions 43→72. The harness is half your agent — here's how to build it like that.#agentic-ai#agent-architecture#tool-calling8 min read
- NOT-005Validate Agent Tool Calls Before They ExecuteAgents generate tool arguments by sampling tokens — malformed calls aren't an edge case, they're a statistical certainty. Here's the five-minute contract check that runs before the side effect, not after the incident.#agentic-ai#ai-security#tool-calling6 min read
- NOT-004Open Knowledge Format (OKF): Google's Answer to the AI Agent Context ProblemGoogle Cloud's OKF is a directory of markdown files with YAML frontmatter — nothing more, and that's the point. A format, not another service, so any agent can consume any knowledge base without an SDK. And v0.2 added the trust layer that makes agent-written knowledge safe to act on.#agentic-ai#ai-security#agent-architecture14 min read
- NOT-003Your Multi-Agent Graph Has No BoundariesThe failure mode nobody designs for: one compromised agent acting as every other agent in the graph. A four-boundary checklist for multi-agent deployments.#agentic-ai#ai-security#multi-agent4 min read
- NOT-002The Best Agent Harness Is the One You Don't NoticeThe harness isn't the interesting part of an agent system. That's exactly why it's the part worth getting right.#agentic-ai#agent-architecture2 min read
- NOT-001Agentic Systems Aren't Apps With Extra StepsGive a model tools and a loop and you haven't built a feature — you've built a distributed system that talks to itself.#agentic-ai#agent-architecture2 min read