Beam / field notes
Loading…
Beam / field notes
Loading…
Beam / field notes
What we're seeing as we watch AI coding agents work — flagged actions, skill/MCP scan findings, and how to keep Claude Code, Codex, and the rest honest without slowing them down.Page 5 of 5
57 posts
Sep 9, 2026 · 11 min readThe Hugging Face agent breach: when the attacker is also an AIOn July 21, 2026, Hugging Face's dataset pipeline was reportedly breached by an autonomous AI system chaining an HDF5 deserialization leak and a Jinja2 template-injection RCE on its own, with no human directing each step. This explains what happened, what is still unclear, and what it means for anyone running local coding agents.
Sep 9, 2026 · 5 min readIntroducing Beam: a local-first security console for your AI coding agentsAI coding agents can read your files, run shell commands, and pull in skills and MCP servers you haven't audited. Beam watches what they do locally, flags what looks wrong, and never ships your activity anywhere.
Sep 9, 2026 · 6 min readMCP security: a practical guide to tool poisoning and rug pullsTool poisoning, tool shadowing, rug pulls, and toxic flows are the four documented MCP attack classes. This guide covers how each works, what the postmark-mcp incident proved, and the honest limits of MCP scanning.
Sep 9, 2026 · 11 min readnpm supply-chain worms are coming for your AI toolingSelf-replicating npm worms have moved from generic package theft to deliberately targeting AI and agent tooling by name. This explains how Shai-Hulud, Mastra AI, axios, node-ipc, and Clinejection actually propagate, and what to check in your own dependency tree.
Sep 9, 2026 · 7 min readNullBulge and the Disney breach: when a fake AI tool becomes a felonyRyan Mitchell Kramer, operating as NullBulge, agreed to plead guilty to two federal felonies after a malicious custom node for ComfyUI stole the credentials behind a 1.1TB Disney Slack leak. This is what a real prosecution over malicious AI tooling looks like, and why it is still rare.
Sep 9, 2026 · 7 min readHow much sensitive data do people share with AI chatbots? The 2026 numbersEmployees paste something sensitive into an AI chatbot roughly every three days, per DLP telemetry. This roundup covers what the 2026 reports actually measured — the data going in, the trust gap, and the breach numbers coming out the other side.
Sep 9, 2026 · 8 min readVibe coding security: a practical checklistVibe coding is fast and genuinely productive, but handing an agent a monorepo and standing production access is how you get the Replit incident. This is a practical, non-preachy checklist for keeping it that way on purpose.
Sep 9, 2026 · 7 min readWhat is AI agent monitoring? Definition, scope, and toolingAI agent monitoring is endpoint-level observation of what an autonomous coding agent actually does: the commands it runs, the files it touches, the MCP servers it calls. It is a different problem from LLM observability.
Sep 9, 2026 · 9 min readWhat is AI safety? Definition, AI safety vs. AI security, and what to do about itAI safety and AI security get used interchangeably and shouldn't be. This covers the actual definition, the four research areas that make up the field, how 2026's governance moved, and — the part most explainers skip — what any of it means for a developer running an AI coding agent today.Page 5 of 5 · 57 posts