PipeLab Blog
AI Agent Security Blog: Research, CVE Analysis, Runtime Defense
Field notes on agent firewalls, MCP security, runtime guardrails, and the people who use them.
Selected field notes
Start with the work behind the product
Three good places to start
Featured
Field
Four Things You Can Check
Four open artifacts for agent security you can check yourself: an evidence standard and checker, a rerunnable attack corpus, signed rules, and a firewall.
Featured
Releases
Pipelock v3.5 Release
Pipelock v3.5 writes Agent Evidence Level records natively, scans WebSocket control frames, and enforces the containment layers a launch applied.
Featured
Releases
Pipelock v3.4 Release
Pipelock v3.4 tightens MCP trust policy, scans media request bodies, hardens credential detection, and adds containment-aware upgrades.
Featured
Pipelock
Pipelock v3.3 Release
Pipelock v3.3 adds subject-keyed denial-of-wallet budgets, encoded-egress detection, opt-in audit-queue encryption, and SNI-required CONNECT.
Featured
Pipelock
Pipelock v3.1 Release
Pipelock v3.1 adds an operator dashboard, free evidence viewer, strict receipt verification, SIEM/fleet readiness, and public benchmark-corpus updates.
Writing archive
Latest field notes
56 posts, newest first
Technical
Agent Egress Base Rates and Alert Precision
Technical
Attack Corpus Governance
Field
Four Things You Can Check
Releases
Pipelock v3.5 Release
Technical
What a Hash Chain Can't Prove
Releases
Pipelock v3.4 Release
Pipelock
Pipelock v3.3 Release
Technical
Benign Set Should Look Malicious
Pipelock
Pipelock v3.1 Release
Pipelock
Pipelock v3.0 Release
Pipelock
Pipelock v2.6 Release
Technical
Stateless MCP and Runtime Security
Deep dives
NSA MCP Security Guidance
Releases
Pipelock v2.5.0 Release
Kubernetes
Per-Pod NetworkPolicy Field Report
Technical
Mediator Receipts: The Attestation Question
Technical
Three HTTPS_PROXY Bypasses
Technical
Capture and Replay Policy
Releases
Agent Egress Control launch
Sre
Wedge Detection
Technical
Block-Reason Headers
Technical
Pipelock Inspection Layers
Kubernetes
subPath ConfigMap Drift
Technical
Webhook vs Egress
Technical
Three-UID Agent Containment
Technical
Politeness vs Enforcement
Releases
Pipelock v2.4.0 Release
Releases
Pipelock v2.3.0 Release
Releases
Pipelock v2.2.0 Release
Industry
Mythos-Ready Runtime Controls
Technical
AI Guardrails Aren't Enough
Industry
AI Security Acquisition Wave
Comparisons
Best AI Agent Security Tools 2026
Technical
Domain Allowlists Aren't Enough
Comparisons
MCP Scanner Comparison
MCP security
State of MCP Security 2026
MCP security
Claude Mythos: Agent Security Risk
Releases
Pipelock Benchmark Scores
Industry
BrowserGate and AI Agent Fingerprinting
Technical
When Your Agent Makes HTTP Requests
Technical
Cross-Request Exfiltration
Comparisons
Agent Egress Security Test Corpus
Technical
Secrets Leak in POST Bodies, Not Just URLs
MCP security
MCP Tool Descriptions Are an Attack Surface
Technical
When the Model Won't Refuse
Industry
CVE-2026-25253 Fix: OpenClaw WebSocket Hijack
Technical
Your AI agent leaks API keys through DNS queries
Technical
Every protocol your agent speaks, scanned
OpSec
Agent Leaked Your AWS Keys: Attack and Fix
Technical
What Is an Agent Firewall?
Industry
EU AI Act Runtime Security
Industry
First AI Agent Espionage Campaign
Releases
What's next for Pipelock: the v0.2 roadmap
OpSec
Wrapping Claude Code MCP
MCP security
283 ClawHub Skills Are Leaking Your Secrets
Technical
Lateral Movement in Multi-Agent LLM Systems
No posts match this filter.
Want the runtime boundary behind this write-up?