{"componentChunkName":"component---src-pages-agent-security-js","path":"/agent-security/","result":{"data":{"allMdx":{"edges":[{"node":{"id":"eb04d9aa-4492-5abb-894a-73c6735e3edb","frontmatter":{"title":"A blocking monitor reads what the agent writes, so the agent can talk to it","date":"2026-09-18T00:00:00.000Z","summary":"Guardrail models judge from the transcript, and the agent authors most of it. Why self-report is a soft gate, and how to give the monitor a view the agent cannot write to.","slug":"a-blocking-monitor-reads-what-the-agent-writes"}}},{"node":{"id":"d66c83f0-4001-55a6-a35b-6ebac64fd7be","frontmatter":{"title":"No single channel carries the injection, so no scanner sees it","date":"2026-09-17T00:00:00.000Z","summary":"A payload split across an MCP tool description, a tool result, and a sampling message defeats every single-channel check. What privilege separation between channels looks like.","slug":"no-single-channel-carries-the-injection"}}},{"node":{"id":"dca96f0f-f153-5fe6-b907-77503bdb0644","frontmatter":{"title":"Poisoned memory survives the session that planted it","date":"2026-09-15T00:00:00.000Z","summary":"An injection an agent judges worth remembering becomes a standing instruction in every later session. Why it persists, and the memory-write control that stops it.","slug":"poisoned-memory-survives-the-session"}}}]}},"pageContext":{}},"staticQueryHashes":[]}