RSS Amplifier

Blog

Deriv<ed>

Learning at the edges of Applied AI—at Deriv

derivai.substack.comSource feed ↗10 posts

Live Last read · last published · next check

Latest posts

Building an automated software development lifecycle with AI agents

Inside an AI-native development pipeline using specs, Planner and Builder agents, independent verification, GitHub Actions, automated quality gates, and human-controlled production releases.

Spec-driven development: When the spec becomes the product

AI can already write code. The bigger shift is what happens when code stops being the primary artefact of software development.

Deriv at AI Malaysia Takeover 2026

11–12 August, The Campus at Ampang

How a fake Claude Code install guide delivered the MacSync malware

A technical analysis of a live Google Ads malvertising campaign abusing Claude AI, Base64-obfuscated shell commands and trusted domains to deliver the MacSync infostealer.

How prompt caching cut our production AI agent input costs by 77%

Inside Deriv’s prompt-caching architecture: deterministic context, longer reusable prefixes, and measured cost reduction at scale.

Killing the credential: Securing cross-cloud AI agents with keyless identity and Dynamic RBAC

How the Agent Auth Hub uses federated identity and human-context verification to control autonomous tool access across clouds

Inside Claude Tag for Slack: The root shell behind the friendly @Claude mention

What employees see as a simple Slack assistant is actually a managed Linux VM with connectors, memory, network controls, and enterprise security trade-offs.

The QA loop that runs itself

How a discovery agent walks user journeys across web and mobile, finds bugs, proves them with generated tests, and hands confirmed defects to a development agent. No one prompts any of it.

How do you give an AI agent a password without losing your mind (or your secrets)?

The authentication and secrets management problem nobody in the agentic AI hype cycle is talking about, and the architecture we built to solve it.

QuiloBook: When the threat walks in through a trusted vendor

Technical analysis of a Rust loader and RAT targeting orgs via compromised vendor communications.