The Agent Is Not the Scanner: Making AI Security Agents Better
Eight months of testing security agents taught me that more scaffolding is not always better. Here’s where skills and MCP helped, where they hurt, and how I route models now.
Security research, malware analysis, DFIR, and notes on building security agents.
Eight months of testing security agents taught me that more scaffolding is not always better. Here’s where skills and MCP helped, where they hurt, and how I route models now.
A hands-on review of a deliberately compromised Linux host: SQL injection, stored XSS, exposed services, backdoor accounts, and the evidence behind each finding.
My first malware analysis: decompiling VajraSpy, tracing its Android workers, and finding how it collects files, messages, contacts, and call logs.