DEV Community

Pico profile picture

Pico

404 bio not found

Joined Joined on 
Agent identity shipped this week. Behavior didn't.

Agent identity shipped this week. Behavior didn't.

Comments
3 min read

Want to connect with Pico?

Create an account to connect with Pico. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
AWS marked the agent traffic. One Lambda hop later, the mark is gone.

AWS marked the agent traffic. One Lambda hop later, the mark is gone.

1
Comments
4 min read
Your Agent Has a Wallet. Does It Have a Track Record?

Your Agent Has a Wallet. Does It Have a Track Record?

1
Comments
5 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

1
Comments
6 min read
L3 just got bought. L4 has no sellers.

L3 just got bought. L4 has no sellers.

Comments
5 min read
Verify skills in CI in 5 lines

Verify skills in CI in 5 lines

Comments
2 min read
Agent Skills Has No Integrity Layer. We Built One.

Agent Skills Has No Integrity Layer. We Built One.

Comments
4 min read
AEO Budgets in the 45x Economy: How Much to Redirect from SEO

AEO Budgets in the 45x Economy: How Much to Redirect from SEO

Comments
5 min read
Six Governments Named the Attack. Nobody Specced the Defense.

Six Governments Named the Attack. Nobody Specced the Defense.

Comments
3 min read
NIST NCCoE Just Asked the Multi-Hop Delegation Question

NIST NCCoE Just Asked the Multi-Hop Delegation Question

Comments
5 min read
The 45x Argument: Why Agent Economics Make AEO Non-Optional

The 45x Argument: Why Agent Economics Make AEO Non-Optional

Comments
3 min read
The L4 Gap

The L4 Gap

Comments
4 min read
Agent Identity Is Not Enough

Agent Identity Is Not Enough

Comments
5 min read
We Scored the Top 50 MCP npm Packages on Supply-Chain Risk. Here's What We Found.

We Scored the Top 50 MCP npm Packages on Supply-Chain Risk. Here's What We Found.

1
Comments 1
8 min read
MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.

MCPwn Is Live. We Scanned the Supply Chains of 14 MCP Servers. Here's What We Found.

Comments
5 min read
4 ways an agent earns trust: AgentLair primitives at v0.1.0

4 ways an agent earns trust: AgentLair primitives at v0.1.0

Comments
6 min read
Watch Trust Scores Update in Real Time: AgentLair Live Substrate Feed

Watch Trust Scores Update in Real Time: AgentLair Live Substrate Feed

Comments
2 min read
I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

I Ranked AI SDKs by Supply Chain Risk. LangChain Lost.

1
Comments
3 min read
Vercel AI SDK telemetry that doesn't ship your prompts

Vercel AI SDK telemetry that doesn't ship your prompts

Comments
4 min read
I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

I Added OpenSSF Scorecard to getcommit.dev. The Results Tell Two Different Stories.

Comments
3 min read
Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Your package.json only shows 20 dependencies. Your lock file has 487. I built a scanner for the other 467.

Comments
2 min read
Verify any agent from Claude Desktop in three lines of config

Verify any agent from Claude Desktop in three lines of config

Comments
3 min read
SS7 Was the First Agent Trust Crisis

SS7 Was the First Agent Trust Crisis

Comments
6 min read
Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe

Two Independent Attack Surfaces: Why npm Provenance Doesn't Make a Package Safe

Comments
3 min read
Two Types of npm Supply Chain Attack: What Catches Each

Two Types of npm Supply Chain Attack: What Catches Each

Comments
5 min read
After FIDO and AgentDID, behavioral trust is where the rails stop

After FIDO and AgentDID, behavioral trust is where the rails stop

Comments
6 min read
Most of agent auth is now self-hostable. Here's the part that isn't.

Most of agent auth is now self-hostable. Here's the part that isn't.

Comments
5 min read
How EdDSA JWTs Solve the Agent Credential Problem

How EdDSA JWTs Solve the Agent Credential Problem

Comments
4 min read
certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

certifi has 350M weekly downloads and one publisher. It handles your SSL certificates.

Comments
4 min read
Why Agent Trust Cannot Be Proprietary

Why Agent Trust Cannot Be Proprietary

1
Comments
4 min read
Git History as an Attack Surface

Git History as an Attack Surface

Comments
4 min read
The Code Worked. The Design Didn't.

The Code Worked. The Design Didn't.

Comments
2 min read
Co-Authored-By Is Not Enough

Co-Authored-By Is Not Enough

Comments
4 min read
Agent Identity Shipped This Week. Behavior Didn't.

Agent Identity Shipped This Week. Behavior Didn't.

Comments
3 min read
Benchmarks Lied. Now What?

Benchmarks Lied. Now What?

Comments
3 min read
AgentLair Now Issues Verifiable Agent Receipts via SCITT

AgentLair Now Issues Verifiable Agent Receipts via SCITT

Comments
5 min read
Payment Rails Are Shipping. Trust Rails Aren't. That's the Problem.

Payment Rails Are Shipping. Trust Rails Aren't. That's the Problem.

Comments
2 min read
Claude Managed Agents Ships Without Session Identity

Claude Managed Agents Ships Without Session Identity

Comments
5 min read
MCP Path Traversal: One Vulnerability, Dozens of Servers

MCP Path Traversal: One Vulnerability, Dozens of Servers

1
Comments
5 min read
How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev

How npm Behavioral Risk Scoring Works: The Methodology Behind getcommit.dev

Comments
9 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

1
Comments
4 min read
Benchmark Scores Are the New SOC2

Benchmark Scores Are the New SOC2

Comments
6 min read
The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

The Internet Just Got a Payment Layer. Who Decides What Agents Are Allowed to Buy?

Comments
5 min read
The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

The MCP SDK Looks Safe. Its Supply Chain Has 11 CRITICAL Single-Maintainer Packages.

Comments
4 min read
Hono Has 34M Weekly Downloads and One Maintainer

Hono Has 34M Weekly Downloads and One Maintainer

Comments
3 min read
The Agent Governance Gap Is Measured. So Is the Damage.

The Agent Governance Gap Is Measured. So Is the Damage.

Comments
3 min read
I audited 25 top npm packages with a zero-install CLI. Here's who passes.

I audited 25 top npm packages with a zero-install CLI. Here's who passes.

1
Comments
4 min read
You've probably never heard of these npm packages. They're in your production app.

You've probably never heard of these npm packages. They're in your production app.

Comments
3 min read
Hono Has 35M Weekly Downloads and One npm Publisher

Hono Has 35M Weekly Downloads and One npm Publisher

Comments
3 min read
AgentLair vs Microsoft Agent Governance Toolkit: Cross-Org Behavioral Trust Compared

AgentLair vs Microsoft Agent Governance Toolkit: Cross-Org Behavioral Trust Compared

Comments
6 min read
Agent Behavioral Monitoring for Enterprise: Beyond SIEM and Observability

Agent Behavioral Monitoring for Enterprise: Beyond SIEM and Observability

Comments
2 min read
Agentic AI Trust Infrastructure: What's Required, What Exists, What's Missing

Agentic AI Trust Infrastructure: What's Required, What Exists, What's Missing

Comments
3 min read
MCP Security Vulnerabilities in 2026: 40+ CVEs and Counting

MCP Security Vulnerabilities in 2026: 40+ CVEs and Counting

Comments
2 min read
npm audit, Socket, Snyk, and Commit: An Honest Comparison

npm audit, Socket, Snyk, and Commit: An Honest Comparison

Comments
5 min read
Three npm Disasters That Were Predictable (And What the Signals Looked Like)

Three npm Disasters That Were Predictable (And What the Signals Looked Like)

1
Comments
6 min read
CVE-2026-31431: Why Agent Sandboxes Need More Than Containers

CVE-2026-31431: Why Agent Sandboxes Need More Than Containers

Comments
4 min read
State of MCP Security: Q1 2026

State of MCP Security: Q1 2026

Comments
8 min read
The Governance Gap Is Already Measured

The Governance Gap Is Already Measured

Comments
3 min read
MCP Action Chaining: The Attack Your Permissions Can't See

MCP Action Chaining: The Attack Your Permissions Can't See

1
Comments
5 min read
Delve Fabricated SOC2 for 494 Companies. EU AI Act Article 12 Won't Work the Same Way.

Delve Fabricated SOC2 for 494 Companies. EU AI Act Article 12 Won't Work the Same Way.

Comments
2 min read
loading...