A living map of what AI coding agents try to do.
Learn the risky patterns behind blocked commands, MCP tools, skills, plugins, and agent prompts. Every public warning is redacted before it teaches anyone else.
Start with the threat, not the jargon
Each guide begins with a plain-English explanation, then opens into deeper controls and examples.
prompt-injection
Prompt injection
A prompt injection is a trick note for an AI tool.
Open guidemcp-tool-poisoning
MCP security
MCP lets agents use tools. Bad tools can lie or overreach.
Open guidesupply-chain
Skill and plugin safety
Agent skills are tiny helpers. Some helpers ask for too much.
Open guidesupply-chain
AI harness supply chain
Install steps can change what your agent trusts.
Open guidesupply-chain
CVE and advisory map
Some known software bugs matter more when agents can use tools.
Open guideprompt-injection
Community warnings
Learn from blocked actions without exposing private work.
Open guideHarness setup guides
Protect the coding tools your team already uses without forcing everyone to become a security expert.
harness
Codex
Terminal-native coding agent with broad shell reach.
Open guideharness
Claude Code
Agentic coding harness with MCP and file access.
Open guideharness
OpenCode
Open-source agent harness for local coding loops.
Open guideharness
GitHub Copilot
IDE and CLI assistant across code and terminal flows.
Open guideharness
Cursor
AI-first IDE with repo and terminal context.
Open guideharness
Gemini CLI
Command-line agent workflow for local projects.
Open guideharness
Hermes
Agent harness for skill and tool orchestration.
Open guideharness
OpenClaw
Open agent workspace with pluggable tools.
Open guideRedacted warnings
Real protection moments, scrubbed for safety before becoming public learning pages.
Safe labs
Practice attack patterns with static simulations. Nothing dangerous executes.
prompt-injection
Prompt injection replay
See how hidden text tries to override your instructions.
Open guidemcp-tool-poisoning
MCP tool poisoning demo
Inspect a fake MCP tool description before it can mislead an agent.
Open guidesecret-exfiltration
Secret exfiltration drill
Practice spotting a secret read request without exposing real secrets.
Open guidesupply-chain
Supply-chain install check
Walk through a simulated install that tries to change agent trust.
Open guideCurated advisories
Only enriched explainers are indexable; raw CVE imports stay hidden until useful.