DEV Community

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
I converted 10 popular APIs to MCP tools. 7 would let an agent delete your data with zero guardrails.

I converted 10 popular APIs to MCP tools. 7 would let an agent delete your data with zero guardrails.

1
Comments
3 min read
Stop Blind-CURLing in Production: How I Built an Audit Layer for API Operations

Stop Blind-CURLing in Production: How I Built an Audit Layer for API Operations

Comments
3 min read
Laravel RateLimiter and a race condition

Laravel RateLimiter and a race condition

1
Comments 6
6 min read
Stop Storing JWTs in Local Storage: The HttpOnly Cookie Architecture 🛡️

Stop Storing JWTs in Local Storage: The HttpOnly Cookie Architecture 🛡️

Comments
2 min read
The Ungoverned Agent Problem: Why MCP Alone Is Not Enough

The Ungoverned Agent Problem: Why MCP Alone Is Not Enough

Comments
4 min read
Web Security Analyzer Pro v3.0 — I built 49 security modules, but I need your help

Web Security Analyzer Pro v3.0 — I built 49 security modules, but I need your help

6
Comments
2 min read
Why Manual Triage Beats Automated Scanners in Modern App Security

Why Manual Triage Beats Automated Scanners in Modern App Security

Comments
1 min read
Why I don’t trust my own deployments (and why you should audit your Security Headers)

Why I don’t trust my own deployments (and why you should audit your Security Headers)

Comments
2 min read
Desktop Agents Are The Next Big Trust Problem

Desktop Agents Are The Next Big Trust Problem

Comments 2
3 min read
Why Every AI Agent Needs a Cryptographic Identity

Why Every AI Agent Needs a Cryptographic Identity

Comments 1
4 min read
From Isolated Team Agents to an Enterprise Agent Harness

From Isolated Team Agents to an Enterprise Agent Harness

Comments
9 min read
Stop Copy-Pasting kubectl Commands to Debug Pods

Stop Copy-Pasting kubectl Commands to Debug Pods

Comments
3 min read
Math.random() Non-Compliant with NIST 800-63B: Adopt Cryptographically Secure Random Number Generators

Math.random() Non-Compliant with NIST 800-63B: Adopt Cryptographically Secure Random Number Generators

Comments
7 min read
9 Seconds: An AI Coding Agent Deleted a Production Database

9 Seconds: An AI Coding Agent Deleted a Production Database

1
Comments 3
5 min read
Compile-time vs runtime: where MCP security actually lives

Compile-time vs runtime: where MCP security actually lives

3
Comments 5
7 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.