Security blog
AI security notes and shipped PRs.
Short notes from OSS security work, followed by the pull requests that shipped.
Read latest postMerged PRs
Recent security work
ci: run libexec wrapper tests
docs: add autonomy downgrade matrix template
feat(project): add coverage threshold gate
feat(project): add grouped Markdown findings export
[security] fix(upload): reject symlinked upload destinations
docs: add shift handoff template appendix
[security] fix(dingtalk): block SSRF in outbound media fetches
[security] fix(container): prevent host file read/delete via container-controlled outbox paths
[security] fix(sandbox): bind local Docker ports to loopback
[security] test(gateway): cover bridge spawn repro path
docs: add authority delegation matrix template
[security] fix(app): validate stored MCP tool URLs
Blog